SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-6553

Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon.

CRITICAL 9.8EPSS 42.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 42.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
42.29% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
quest/privilege manager for unix
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.