PT-2024-15808 · Nsasoft · Nsasoft Sharealarmpro
Fernando.Mengali
·
Published
2024-01-21
·
Updated
2024-10-21
·
CVE-2024-0772
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Nsasoft ShareAlarmPro version 2.1.4
Description
A vulnerability was found in the Registration Handler component of Nsasoft ShareAlarmPro. The manipulation of the
Name/Key argument leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.Recommendations
For Nsasoft ShareAlarmPro version 2.1.4, consider restricting local access to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid manipulating the
Name/Key argument in the Registration Handler component. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nsasoft Sharealarmpro