PT-2026-33722 · Adm · Adm
Yu-Xiang Huang
·
Published
2026-04-20
·
Updated
2026-04-20
·
CVE-2026-6643
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ADM versions 4.1.0 through 4.3.3.RR42
ADM versions 5.0.0 through 5.1.2.REO1
Description
A stack-based buffer overflow exists in the VPN Clients. The issue is caused by the use of unbounded sscanf() and the direct passing of user-controlled data to printf(). Because Position Independent Executable (PIE) and Stack Canary protections are absent, an authenticated remote attacker can execute arbitrary code as the web server user.
Recommendations
Update versions 4.1.0 through 4.3.3.RR42 to a version containing the fix.
Update versions 5.0.0 through 5.1.2.REO1 to a version containing the fix.
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adm