Buffer Overflow Vulnerability in VX Search Enterprise by Velocis
CVE-2017-13708

9.8CRITICAL

Key Information:

Vendor

Vxsearch

Status
Vendor
CVE Published:
31 August 2017

What is CVE-2017-13708?

A buffer overflow vulnerability exists in VX Search Enterprise 10.0.14, specifically within its web server service. This flaw allows remote attackers to craft specific GET requests that can lead to the execution of arbitrary code on the affected system. Exploiting this vulnerability can compromise the integrity and security of affected installations, enabling unauthorized actions by an attacker.

References

EPSS Score

70% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.