CVE-2019-15683 is a critical stack buffer overflow vulnerability affecting TurboVNC servers, specifically in commits prior to cea98166008301e614e0d36776bf9435a536136e. This flaw, rated 9.8 Critical on CVSSv3.1, allows for remote code execution with high impact on confidentiality, integrity, and availability, despite requiring prior authorization on the server. While the attack is network-exploitable with low complexity, there is currently no evidence of active exploitation, nor are public exploit modules available in Metasploit or Nuclei. However, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.3CPE matchmatch criteria | cpe:2.3:a:turbovnc:turbovnc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.