Security Advisory

CVE-2019-3955

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-06-07 20:00:55
Last updated 2024-08-04 19:26:27
Assigner tenable
State PUBLISHED

Description

Dameware Remote Mini Control version 12.1.0.34 and prior contains a unauthenticated remote heap overflow due to the server not properly validating RsaPubKeyLen during key negotiation. An unauthenticated remote attacker can cause a heap buffer overflow by specifying a large RsaPubKeyLen, which could cause a denial of service.