Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-18257

Опубликовано: 17 дек. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist in the file transfer service listening on the TCP port. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with the privileges of the user running DiagAnywhere Server.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:advantech:diaganywhere:*:*:*:*:*:*:*:*
Версия до 3.07.11 (включая)

EPSS

Процентиль: 79%
0.01215
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-121
CWE-787

Связанные уязвимости

github
больше 3 лет назад

In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist in the file transfer service listening on the TCP port. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with the privileges of the user running DiagAnywhere Server.

EPSS

Процентиль: 79%
0.01215
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-121
CWE-787