QID 375513
QID 375513: Dameware Mini remote control Unauthenticated Remote Buffer Over-Read Vulnerability
Solarwinds Dameware Remote Mini Controller is a software for assisting in remote desktop connections for helpdesk support.
CVE-2019-3955: Dameware Remote Mini Control version 12.1.0.34 and prior contains a unauthenticated remote heap overflow due to the server not properly validating RsaPubKeyLen during key negotiation.
CVE-2019-3956: Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating CltDHPubKeyLen during key negotiation.
CVE-2019-3957: Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation.
Affected Version:
SolarWinds Dameware 12.1.0.34 and prior.
QID Detection Logic(Authenticated)
QID will to find the affected version of SolarWinds Dameware through registry key from installed location.
An unauthenticated remote attacker can cause a heap buffer overflow by specifying a large RsaPubKeyLen, which could cause a denial of service.
Please refer DameWare
CVEs related to QID 375513
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Dameware |
|