CVE Feed

    Dashboard / CVE / CVE-2018-6892

    CVE-2018-6892

    An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing arbitrary code execution.

    Published:Feb 11, 2018
    Last Modified:Nov 21, 2024
    EPS:Feb 11, 2018
    EPSS Score:0.90167
    CVSS Score:9.8

    Affected Products

    Vendor
    Cloudme
    Product
    Sync

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High