Unauthenticated Remote Buffer Over-read in Dameware Remote Mini Control Version 12.1.0.34 and Prior

Unauthenticated Remote Buffer Over-read in Dameware Remote Mini Control Version 12.1.0.34 and Prior

CVE-2019-3956 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:N/A:P

Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating CltDHPubKeyLen during key negotiation, which could crash the application or leak sensitive information.

Learn more about our Cis Benchmark Audit For Server Software.