CVE-2009-3861 describes a stack-based buffer overflow vulnerability in SafeNet SoftRemote versions 10.8.5 (Build 2) and 10.3.5 (Build 6), and potentially other versions prior to 10.8.9. This flaw allows a local attacker to execute arbitrary code by supplying an excessively long string within the TREENAME or GROUPNAME fields of a Policy file (spd). The vulnerability carries a CVSS score of 6.9, indicating a moderate to high severity. Its attack vector is local (AV:L) with medium attack complexity (AC:M), but successful exploitation can lead to complete compromise of confidentiality, integrity, and availability (C:C/I:C/A:C). While not listed on the CISA KEV catalog, exploit code for this vulnerability is publicly available, including a Metasploit module specifically targeting the GROUPNAME buffer overflow. Despite this, there is no evidence of active exploitation, and community discussion or media coverage for this CVE is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.8.8CPE matchmatch criteria | cpe:2.3:a:safenet-inc:softremote:*:*:*:*:*:*:*:* | ||
1.7.1CPE matchmatch criteria | cpe:2.3:a:safenet-inc:softremote:1.7.1:*:*:*:*:*:*:* | ||
1.7.2CPE matchmatch criteria | cpe:2.3:a:safenet-inc:softremote:1.7.2:*:*:*:*:*:*:* | ||
1.7.7CPE matchmatch criteria | cpe:2.3:a:safenet-inc:softremote:1.7.7:*:*:*:*:*:*:* | ||
1.8.1CPE matchmatch criteria | cpe:2.3:a:safenet-inc:softremote:1.8.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.