6.8
CVSSv2

CVE-2019-13494

Published: 12/07/2019 Updated: 24/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

nodeimp.exe in Castle Rock SNMPc prior to 9.0.12.1 and 10.x prior to 10.0.9 has a stack-based buffer overflow via a long variable string in a Map Objects text file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

castlerock simple network management protocol console

Exploits

#!/usr/bin/python # -*- coding: utf-8 -*- #--------------------------------------------------------------------# # Exploit: SNMPc Enterprise Edition (9 & 10) (Mapping File Name BOF) # # Date: 11 July 2019 # # Exploit Author: @xerubus | mogozobocom # # Vendor Homepag ...
SNMPc Enterprise Edition versions 9 and 10 suffer from a mapping filename buffer overflow vulnerability ...