PT-2014-5338 · Solarwinds · Solarwinds Network Configuration Manager

Andrea Micalizzi

+1

·

Publicado

2014-05-19

·

Atualizado

2014-08-07

·

CVE-2014-3459

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SolarWinds Network Configuration Manager versions prior to 7.3
Description The issue is related to a heap-based buffer overflow that allows remote attackers to execute arbitrary code. This is achieved via the PEstrarg1 property.
Recommendations For versions prior to 7.3, update to version 7.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the PEstrarg1 property to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3459
ZDI-14-133

Produtos afetados

Solarwinds Network Configuration Manager