CVE-2019-3712

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
07/03/2019
Last modified:
09/10/2019

Description

Dell WES Wyse Device Agent versions prior to 14.1.2.9 and Dell Wyse ThinLinux HAgent versions prior to 5.4.55 00.10 contain a buffer overflow vulnerability. An unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code on the system with privileges of the FTP client by sending specially crafted input data to the affected system. The FTP code that contained the vulnerability has been removed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:windows_embedded_standard_wyse_device_agent:*:*:*:*:*:*:*:* 14.1.2.9 (excluding)
cpe:2.3:a:dell:wyse_thinlinux_hagent:*:*:*:*:*:*:*:* 5.4.55_00.10 (excluding)