VDB
CVE-2019-18257
CVE-2019-18257
PUBLISHED
CVSS 9.800000190734863 CRITICAL
In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist in the file transfer service listening on the TCP port. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with the privileges of the user running DiagAnywhere Server.
EPSS 2.77% · 85.2th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
2.77%
85.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Advantech DiagAnywhere Server | Versions 3.07.11 and prior |
| advantech | diaganywhere | 0 |
Timeline
- Dec 12, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 12, 2023 EPSS Score
- Jul 15, 2023 EPSS Score