IM
IronMonkey Threat Research

CVE-2024-6918 HIGH

Published: 2024-08-20 | Last Modified: 2026-04-15 | Status: Deferred

Description

CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the Accutech Manager when receiving a specially crafted request over port 2536/TCP.

Additional Descriptions (1)

CWE-120: Existe una vulnerabilidad de copia del búfer sin verificar el tamaño de la entrada ('Desbordamiento del búfer clásico') que podría provocar un bloqueo de Accutech Manager al recibir una solicitud especialmente manipulada a través del puerto 2536/TCP.

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 3.9

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-120
Notification
Message here