AMPPS 2.7 contains a denial of service vulnerability that allows remote attackers to crash the service by sending malformed data to the default HTTP port. Attackers can establish multiple socket connections and transmit invalid payloads to exhaust server resources and cause service unavailability.
History

Mon, 09 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Ampps
Ampps ampps
Vendors & Products Ampps
Ampps ampps

Fri, 06 Mar 2026 12:30:00 +0000

Type Values Removed Values Added
Description AMPPS 2.7 contains a denial of service vulnerability that allows remote attackers to crash the service by sending malformed data to the default HTTP port. Attackers can establish multiple socket connections and transmit invalid payloads to exhaust server resources and cause service unavailability.
Title AMPPS 2.7 Denial of Service via Malformed Socket Connection
First Time appeared Softaculous
Softaculous ampps
Weaknesses CWE-1188
CPEs cpe:2.3:a:softaculous:ampps:2.7:*:*:*:*:*:*:*
Vendors & Products Softaculous
Softaculous ampps
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-09T19:04:46.611Z

Reserved: 2026-03-06T11:29:34.018Z

Link: CVE-2018-25169

cve-icon Vulnrichment

Updated: 2026-03-09T19:04:42.528Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-06T13:15:58.057

Modified: 2026-03-09T13:35:34.633

Link: CVE-2018-25169

cve-icon Redhat

No data.