VulnerabilityModified
CVE-2011-3176
Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x4c request.
HIGH 10.0EPSS 70.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 70.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x4c request.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 70.07% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- novell/zenworks configuration management
- Source
- cve@mitre.org
References
- http://download.novell.com/Download?buildid=rs4B5jhWKf8~
- http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5127930.html
- http://www.exploit-db.com/exploits/19959
- http://www.novell.com/support/viewContent.do?externalId=7010044
- http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=974
- http://download.novell.com/Download?buildid=rs4B5jhWKf8~
- http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5127930.html
- http://www.exploit-db.com/exploits/19959
- http://www.novell.com/support/viewContent.do?externalId=7010044
- http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=974
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.