LanSpy version 2.0.1.159 is vulnerable to a local buffer overflow condition in its scan field functionality. By submitting oversized input consisting of 688 bytes of padding followed by 4 bytes of controlled data, an attacker can overwrite the instruction pointer, potentially leading to application crash or arbitrary code execution. The vulnerability carries a CVSS v3.1 score of 8.4 (HIGH) with a local attack vector requiring no privileges or user interaction. All impact categories—confidentiality, integrity, and availability—are rated as HIGH, indicating complete system compromise is possible if code execution is achieved. There is no evidence of active exploitation in the wild. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog, the Hot List remains inactive, and the EPSS score of 0.00013 indicates minimal real-world prevalence compared to other vulnerabilities. However, the relatively straightforward nature of the overflow and availability of proof-of-concept details warrant monitoring for future exploitation activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.1.159CPE matchmatch criteria | cpe:2.3:a:lizardsystems:lanspy:2.0.1.159:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.