Unauthenticated Remote Buffer Over-read in Dameware Remote Mini Control Version 12.1.0.34 and Prior

Unauthenticated Remote Buffer Over-read in Dameware Remote Mini Control Version 12.1.0.34 and Prior

CVE-2019-3957 · HIGH Severity

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.

Learn more about our Cis Benchmark Audit For Server Software.