Vulnerability Description
10-Strike Network Scanner 3.0 contains a local buffer overflow vulnerability in the host name field that allows attackers to bypass SafeSEH protections and execute arbitrary code. Attackers can craft a malicious payload in the host name or address field and trigger the vulnerability through the Trace route or System information functions to achieve code execution.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.10-strike.com/
- https://www.exploit-db.com/exploits/44841
- https://www.vulncheck.com/advisories/10-strike-network-scanner-local-buffer-over
FAQ
What is CVE-2018-25345?
CVE-2018-25345 is a vulnerability with a CVSS score of 8.4 (HIGH). 10-Strike Network Scanner 3.0 contains a local buffer overflow vulnerability in the host name field that allows attackers to bypass SafeSEH protections and execute arbitrary code. Attackers can craft ...
How severe is CVE-2018-25345?
CVE-2018-25345 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25345?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.