SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-13696

A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and…

CRITICAL 9.8EPSS 78.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 78.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server component. Successful exploitation of the software will allow an attacker to gain complete access to the system with NT AUTHORITY / SYSTEM level privileges. The vulnerability lies due to improper handling and sanitization of the incoming request.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
78.31% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
flexense/dupscout · flexense/disksavvy · flexense/syncbreeze · flexense/diskpulse
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.