CVE-2019-18257 PUBLISHED CVSS 9.800000190734863 CRITICAL

In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist in the file transfer service listening on the TCP port. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with the privileges of the user running DiagAnywhere Server.

EPSS 0.60% · 69.4th percentile

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.60%
69.4th percentile

Affected Products

VendorProductVersions
n/aAdvantech DiagAnywhere ServerVersions 3.07.11 and prior
advantechdiaganywhere0

Timeline

References

Open in Interactive Console →