PT-2019-1399 · Wibu Systems · Wibukey Network Server Management
Published
2019-02-05
·
Updated
2022-04-19
·
CVE-2018-3991
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WibuKey Network Server Management version 6.40.2402.500
Description
The issue is related to a heap overflow vulnerability in the WkbProgramLow function. This can be exploited by sending specially crafted TCP packets, potentially leading to remote code execution and denial of service. The vulnerability can be triggered by sending a malformed TCP packet to port 22347/TCP.
Recommendations
For version 6.40.2402.500, consider restricting access to port 22347/TCP to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the WkbProgramLow function until the issue is resolved.
Exploit
Fix
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wibukey Network Server Management