PT-2019-1399 · Wibu Systems · Wibukey Network Server Management

Published

2019-02-05

·

Updated

2022-04-19

·

CVE-2018-3991

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WibuKey Network Server Management version 6.40.2402.500
Description The issue is related to a heap overflow vulnerability in the WkbProgramLow function. This can be exploited by sending specially crafted TCP packets, potentially leading to remote code execution and denial of service. The vulnerability can be triggered by sending a malformed TCP packet to port 22347/TCP.
Recommendations For version 6.40.2402.500, consider restricting access to port 22347/TCP to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the WkbProgramLow function until the issue is resolved.

Exploit

Fix

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00771
CVE-2018-3991

Affected Products

Wibukey Network Server Management