CVE-2019-18326Out-of-bounds Write in Siemens Sppa-t3000 Ms3000 Migration Server

Severity
9.8CRITICALNVD
EPSS
1.4%
top 19.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12
Latest updateMay 24

Description

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18323, CVE-2019-18324, CVE-2019-18325, CVE-2019-18327, CVE-2019-18328, CVE-2019-18329, and CVE-2019-18330. Please note that an attacker needs to have network access to the M

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-f4hc-mjp6-wmcp: A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions)2022-05-24
CVEList
CVE-2019-18326: A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions)2019-12-12