Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-17996

Опубликовано: 06 фев. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Низкий

Описание

A buffer overflow vulnerability in "Add command" functionality exists in Flexense SyncBreeze Enterprise <= 10.3.14. The vulnerability can be triggered by an authenticated attacker who submits more than 5000 characters as the command name. It will cause termination of the SyncBreeze Enterprise server and possibly remote command execution with SYSTEM privilege.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flexense:syncbreeze:*:*:*:*:enterprise:*:*:*
Версия до 10.3.14 (включая)

EPSS

Процентиль: 88%
0.04149
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

A buffer overflow vulnerability in "Add command" functionality exists in Flexense SyncBreeze Enterprise <= 10.3.14. The vulnerability can be triggered by an authenticated attacker who submits more than 5000 characters as the command name. It will cause termination of the SyncBreeze Enterprise server and possibly remote command execution with SYSTEM privilege.

EPSS

Процентиль: 88%
0.04149
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-119