First published: Fri Jun 07 2019(Updated: )
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dameware Mini Remote Control | <=12.1.0.34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3957 is rated as a medium severity vulnerability due to its potential to crash applications and leak sensitive information.
To mitigate CVE-2019-3957, upgrade to a version of SolarWinds DameWare Mini Remote Control later than 12.1.0.34.
CVE-2019-3957 is classified as an unauthenticated remote buffer over-read vulnerability.
Exploiting CVE-2019-3957 could lead to application crashes or unauthorized disclosure of sensitive information.
CVE-2019-3957 affects all versions of SolarWinds DameWare Mini Remote Control up to and including 12.1.0.34.