CVE-2017-13696
A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 78.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server component. Successful exploitation of the software will allow an attacker to gain complete access to the system with NT AUTHORITY / SYSTEM level privileges. The vulnerability lies due to improper handling and sanitization of the incoming request.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 78.31% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- flexense/dupscout · flexense/disksavvy · flexense/syncbreeze · flexense/diskpulse
- Source
- cve@mitre.org
References
- https://www.exploit-db.com/exploits/42557Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42558/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42559/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42560/Exploit, Third Party Advisory, VDB Entry
- https://www.rapid7.com/db/modules/exploit/windows/http/disk_pulse_enterprise_getThird Party Advisory
- https://www.exploit-db.com/exploits/42557Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42558/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42559/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42560/Exploit, Third Party Advisory, VDB Entry
- https://www.rapid7.com/db/modules/exploit/windows/http/disk_pulse_enterprise_getThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.