CVE-2011-3493 identifies multiple stack-based buffer overflows within the DH_OneSecondTick function of Cogent DataHub versions 7.1.1.63 and earlier. This vulnerability allows an unauthenticated remote attacker to trigger a denial of service or potentially execute arbitrary code by sending overly long 'domain', 'report_domain', 'register_datahub', or 'slave' commands. With a critical CVSS score of 10.0, this flaw is easily exploitable over the network with low complexity. While not currently listed on CISA's Known Exploited Vulnerabilities catalog, public exploit code is available on ExploitDB, and it remains on a "Hot List" indicating its continued risk and relevance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.1.1.63CPE matchmatch criteria | cpe:2.3:a:cogentdatahub:cogent_datahub:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:cogentdatahub:cogent_datahub:7.0:*:*:*:*:*:*:* | ||
7.0.2CPE matchmatch criteria | cpe:2.3:a:cogentdatahub:cogent_datahub:7.0.2:*:*:*:*:*:*:* | ||
7.1.0CPE matchmatch criteria | cpe:2.3:a:cogentdatahub:cogent_datahub:7.1.0:*:*:*:*:*:*:* | ||
7.1.1CPE matchmatch criteria | cpe:2.3:a:cogentdatahub:cogent_datahub:7.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.