PT-2026-44541 · Lakeside · Systrack Agent

Vulncheck

·

Published

2026-05-28

·

Updated

2026-05-28

·

CVE-2026-39929

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially crafted UDP packet. Attackers can send a malformed packet with an invalid memory address at offset 0x4 in the payload to trigger an access violation and cause a denial of service.

Fix

Improper Check for Exceptional Conditions

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-39929

Affected Products

Systrack Agent