CVE-2019-3712
Summary
| CVE | CVE-2019-3712 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-07 18:29:00 UTC |
| Updated | 2019-10-09 23:49:00 UTC |
| Description | Dell WES Wyse Device Agent versions prior to 14.1.2.9 and Dell Wyse ThinLinux HAgent versions prior to 5.4.55 00.10 contain a buffer overflow vulnerability. An unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code on the system with privileges of the FTP client by sending specially crafted input data to the affected system. The FTP code that contained the vulnerability has been removed. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dell | Windows Embedded Standard Wyse Device Agent | All | All | All | All |
| Application | Dell | Windows Embedded Standard Wyse Device Agent | All | All | All | All |
| Application | Dell | Wyse Thinlinux Hagent | All | All | All | All |
| Application | Dell | Wyse Thinlinux Hagent | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory |
| DSA-2019-039: Dell Wyse Device Agent Buffer Overflow Vulnerability | Dell US | MISC | www.dell.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Dell would like to thank Jason Larsen of IOActive for reporting this vulnerability.
There are currently no legacy QID mappings associated with this CVE.