CVE-2019-18257

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
17/12/2019
Last modified:
22/10/2020

Description

In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist in the file transfer service listening on the TCP port. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with the privileges of the user running DiagAnywhere Server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:advantech:diaganywhere:*:*:*:*:*:*:*:* 3.07.11 (including)


References to Advisories, Solutions, and Tools