CVE-2019-8260: Critical severity ultravnc vulnerability
Published Mar 5, 2019
·Updated
UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused by multiplication overflow. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1200.
Affected Software
13 affected componentsFixes available
Uvnc Ultravnc<1.2.2.3
Siemens SIMATIC HMI Comfort Outdoor Panels 7’ and 15’ (incl. SIPLUS variants) Update 4<16
16
Siemens SIMATIC HMI Comfort Panels 4’to 22’ (incl. SIPLUS variants) Update 4<16
16
Siemens SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900, and KTP900F Update 4<16
16
Siemens SIMATIC WinCC Runtime Advanced Update 4<16
16
Siemens SINAMICS GH150
Siemens SINAMICS GL150 (with option X30)
Siemens SINAMICS GM150 (with option X30)
Siemens SINAMICS SH150
Siemens SINAMICS SL150
Siemens SINAMICS SM120
Siemens SINAMICS SM150
Siemens SINAMICS SM150i
Event History
Mar 5, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is the severity of CVE-2019-8260?
CVE-2019-8260 is considered a critical vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2019-8260?
To fix CVE-2019-8260, update UltraVNC to revision 1200 or newer.
3
What types of software are affected by CVE-2019-8260?
CVE-2019-8260 affects UltraVNC versions up to 1.2.2.3 and various Siemens SINAMICS products.
4
Can CVE-2019-8260 be exploited remotely?
Yes, CVE-2019-8260 can be exploited remotely via network connectivity.
5
What kind of vulnerability is CVE-2019-8260?
CVE-2019-8260 is an out-of-bounds read vulnerability caused by a multiplication overflow.