PT-2019-16805 · Dameware · Dameware Mini Remote Control
Published
2019-06-07
·
Updated
2021-07-21
·
CVE-2019-3956
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Dameware Remote Mini Control versions 12.1.0.34 and prior
Description
The issue is related to an unauthenticated remote buffer over-read due to improper validation of
CltDHPubKeyLen during key negotiation. This could potentially crash the application or leak sensitive information.Recommendations
For Dameware Remote Mini Control versions 12.1.0.34 and prior, update to a version that fixes the improper validation of
CltDHPubKeyLen to prevent potential crashes or information leaks.Exploit
Fix
RCE
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dameware Mini Remote Control