6.8
CVSSv2

CVE-2015-2898

Published: 29/10/2015 Updated: 29/10/2015
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple stack-based buffer overflows in Medicomp MEDCIN Engine prior to 2.22.20153.226 might allow remote malicious users to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function.

Vulnerable Product Search on Vulmon Subscribe to Product

medicomp medcin engine

Github Repositories

CVE-2015-2898-2901, CVE-2015-6006 POC Exploit & Metasploit module This is a proof of concept exploit for version 22220142166 and prior of the MEDCIN Engine (medcinservexe or medcinservv22exe) More details about the vulnerabilities can be found at: wwwsecuriferacom/blog/2016/01/06/medcin-engine-exploitation-part-2-cve-2015-2898-2901-cve-2015-6006/ https:/