PT-2019-1399 · Wibu Systems · Wibukey Network Server Management
Publicado
2019-02-05
·
Atualizado
2022-04-19
·
CVE-2018-3991
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WibuKey Network Server Management version 6.40.2402.500
Description
The issue is related to a heap overflow vulnerability in the WkbProgramLow function. This can be exploited by sending specially crafted TCP packets, potentially leading to remote code execution and denial of service. The vulnerability can be triggered by sending a malformed TCP packet to port 22347/TCP.
Recommendations
For version 6.40.2402.500, consider restricting access to port 22347/TCP to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the WkbProgramLow function until the issue is resolved.
Exploit
Correção
Buffer Overflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Wibukey Network Server Management