CVE-2019-3563 is a critical vulnerability affecting Wangle versions prior to v2019.04.22.00. It stems from incorrect buffer advancement logic within Wangle's LineBasedFrameDecoder, which can lead to a buffer underflow. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a severe risk with network-based exploitation, low attack complexity, and high impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community attention with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2019.04.22.00CPE matchmatch criteria | cpe:2.3:a:facebook:wangle:*:*:*:*:*:*:*:* | ||
< v2019.04.22.00CPE match | cpe:2.3:a:facebook:wangle:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.