Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-12786

Опубликовано: 22 авг. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Средний

Описание

Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when ACL modifications are applied. This could be leveraged by remote, unauthenticated attackers to gain resultant privileged (root) code execution on the switch, because there is a stack-based buffer overflow during unserialization of packet data.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:noviflow:noviware:*:*:*:*:*:*:*:*
Версия до 400.2.6 (включая)

EPSS

Процентиль: 97%
0.35137
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when ACL modifications are applied. This could be leveraged by remote, unauthenticated attackers to gain resultant privileged (root) code execution on the switch, because there is a stack-based buffer overflow during unserialization of packet data.

fstec
больше 8 лет назад

Уязвимость компонента ACL операционной системы NoviWare, позволяющая нарушителю получить доступ к сетевому интерфейсу службы novi_process_manager_daemon service и выполнить произвольный код в привилегированном режиме коммутатора

EPSS

Процентиль: 97%
0.35137
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-119