9.8
CVSSv3

CVE-2017-17968

Published: 29/12/2017 Updated: 16/01/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and previous versions could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP response.

Vulnerable Product Search on Vulmon Subscribe to Product

xi-soft nettransport download manager

Exploits

#!/usr/bin/pythion # Exploit Title: Buffer overflow in NetTransport Download Manager - Version 296L (DEP Bypass) # CVE: CVE-2017-17968 # Date: 28-12-2017 # Software Link: xi-softcom/downloads/NXSetup_x86zip # Exploit Author: Author: Aloyce J Makalanga # Contact: twittercom/aloycemjr # Vendor Homepage: xi-softcom/default ...
NetTransport Download Manager version 296L suffers from a buffer overflow vulnerability ...