Angry IP Scanner version 3.5.3 contains a buffer overflow vulnerability in its preferences dialog that can be exploited by local attackers to cause application denial of service. The flaw allows an attacker to crash the application by inserting an excessively large string into the display preferences field, requiring only that the attacker have local system access and user interaction capabilities. The vulnerability has a CVSS score of 6.2 (medium severity) with a local attack vector and low complexity. While the attack does not compromise confidentiality or integrity, it produces a high impact on availability by crashing the application. The attack requires no special privileges and minimal user interaction, making it relatively straightforward to execute for any local user. There is currently no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog, and the EPSS score of 0.00012 indicates minimal community attention and exploitation likelihood. The relatively low FAUCET risk score of 43/100 further suggests this is not a priority threat for immediate remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.5.3CPE matchmatch criteria | cpe:2.3:a:angryip:angry_ip_scanner:3.5.3:*:*:*:*:windows:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.