CVE-2019-3957: Input Validation
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3957?
CVE-2019-3957 is rated as a medium severity vulnerability due to its potential to crash applications and leak sensitive information.
How do I fix CVE-2019-3957?
To mitigate CVE-2019-3957, upgrade to a version of SolarWinds DameWare Mini Remote Control later than 12.1.0.34.
What type of vulnerability is CVE-2019-3957?
CVE-2019-3957 is classified as an unauthenticated remote buffer over-read vulnerability.
What could be the impact of exploiting CVE-2019-3957?
Exploiting CVE-2019-3957 could lead to application crashes or unauthorized disclosure of sensitive information.
Which software versions are affected by CVE-2019-3957?
CVE-2019-3957 affects all versions of SolarWinds DameWare Mini Remote Control up to and including 12.1.0.34.