PT-2024-15808 · Nsasoft · Nsasoft Sharealarmpro

Fernando.Mengali

·

Published

2024-01-21

·

Updated

2024-10-21

·

CVE-2024-0772

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Nsasoft ShareAlarmPro version 2.1.4
Description A vulnerability was found in the Registration Handler component of Nsasoft ShareAlarmPro. The manipulation of the Name/Key argument leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Recommendations For Nsasoft ShareAlarmPro version 2.1.4, consider restricting local access to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid manipulating the Name/Key argument in the Registration Handler component. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-0772

Affected Products

Nsasoft Sharealarmpro