An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate at which such messages are sent.
8 months ago
is owned and operated by Vicarius Ltd. (the “Company”). All information
contained on the Website is purely for informational, and educational
purposes and should be independently verified and confirmed. Vicarius
does not accept any liability for any loss or damage whatsoever caused
in reliance upon such information or services. No statements or
information presented in any form by Vicarius is intended as fact, and
you agree that you will not consider the statements or information
presented on the Website as fact or as a guarantee of performance.