Buffer Overflow Vulnerability in DiskSavvy Enterprise by DiskSavvy
CVE-2017-6187

9.8CRITICAL

Key Information:

Vendor

Disksavvy

Vendor
CVE Published:
22 February 2017

What is CVE-2017-6187?

A buffer overflow vulnerability exists in the built-in web server of DiskSavvy Enterprise 9.4.18, enabling remote attackers to execute arbitrary code. This vulnerability arises due to improper handling of long URIs in GET requests. Successful exploitation can allow an attacker to gain control over the affected system, leading to potentially severe consequences for the security of the application and the data it processes.

References

EPSS Score

69% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.