VulnerabilityModified
CVE-2008-2161
Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a long TFTP error packet.
HIGH 10.0EPSS 65.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 65.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a long TFTP error packet. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 65.28% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- tftp/tftp server sp
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/30147Vendor Advisory
- http://www.securityfocus.com/bid/29111
- http://www.vupen.com/english/advisories/2008/1468/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42298
- https://www.exploit-db.com/exploits/5563
- http://secunia.com/advisories/30147Vendor Advisory
- http://www.securityfocus.com/bid/29111
- http://www.vupen.com/english/advisories/2008/1468/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42298
- https://www.exploit-db.com/exploits/5563
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.