vendor:
SysGauge
by:
Chris Higgins, Peter Baris
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: SysGauge
Affected Version From: SysGauge 1.5.18
Affected Version To: SysGauge 1.5.18
Patch Exists: NO
Related CWE: EDB-41479
CPE: a:flexense:sysgauge
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2017
SysGauge SMTP Validation Buffer Overflow
This module will setup an SMTP server expecting a connection from SysGauge 1.5.18 via its SMTP server validation. The module sends a malicious response along in the 220 service ready response and exploits the client, resulting in an unprivileged shell.
Mitigation:
No known mitigation or remediation for this vulnerability