CVE-2014-3459: Buffer Overflow
Published Aug 7, 2014
·Updated
Heap-based buffer overflow in SolarWinds Network Configuration Manager (NCM) before 7.3 allows remote attackers to execute arbitrary code via the PEstrarg1 property.
Affected Software
3 affected components
SolarWinds Network Configuration Manager<=7.2.2
SolarWinds Network Configuration Manager=7.2.0
SolarWinds Network Configuration Manager=7.2.1
Event History
Aug 7, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3459?
CVE-2014-3459 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2014-3459?
To fix CVE-2014-3459, upgrade SolarWinds Network Configuration Manager to version 7.3 or later.
3
What types of attacks can CVE-2014-3459 facilitate?
CVE-2014-3459 can facilitate remote code execution attacks by exploiting a heap-based buffer overflow.
4
Which versions of SolarWinds Network Configuration Manager are affected by CVE-2014-3459?
CVE-2014-3459 affects versions before 7.3, including 7.2.0, 7.2.1, and 7.2.2.
5
Can CVE-2014-3459 be exploited remotely?
Yes, CVE-2014-3459 can be exploited remotely by attackers to execute arbitrary code.