CVE-2019-3957

7.4HIGH

Key Information:

Vendor
Solarwinds
Vendor
CVE Published:
7 June 2019

Summary

Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.

Affected Version(s)

Solarwinds Dameware Remote Mini Controller All versions prior to version 12.1.0.34

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.