CVE-2019-3955 describes an unauthenticated remote heap overflow vulnerability in Dameware Remote Mini Control versions 12.1.0.34 and prior. This flaw allows an unauthenticated attacker to trigger a denial of service by sending a crafted RsaPubKeyLen value during key negotiation, leading to a heap buffer overflow. Rated with a CVSS score of 7.5 (High), the vulnerability is easily exploitable over the network with no user interaction required. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has not been added to CISA's KEV catalog, indicating no active exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.1.0.34CPE matchmatch criteria | cpe:2.3:a:dameware:remote_mini_control:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Dameware Remote Mini Controller Multiple Vulnerabilities
Jun 6, 2019Dameware Remote Mini Controller Multiple Vulnerabilities
Jun 6, 2019Dameware Remote Mini Controller Multiple Vulnerabilities
Jun 6, 2019Dameware Remote Mini Controller Multiple Vulnerabilities
Jun 6, 2019Dameware Remote Mini Controller Multiple Vulnerabilities
Jun 6, 2019Dameware Remote Mini Controller Multiple Vulnerabilities
Jun 6, 2019