CVE-2019-3980 is a critical vulnerability affecting SolarWinds Dameware Mini Remote Control agent v12.1.0.89. It allows an unauthenticated, remote attacker to upload and execute arbitrary code under the Local System account by exploiting the smart card authentication feature. This vulnerability has a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, its high EPSS and FAUCET Risk Score indicate a significant potential threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1.0.89CPE matchmatch criteria | cpe:2.3:a:solarwinds:dameware_mini_remote_control:12.1.0.89:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
SolarWinds Dameware Mini Remote Control Unauthenticated RCE
Sep 30, 2019SolarWinds Dameware Mini Remote Control Unauthenticated RCE
Sep 30, 2019SolarWinds Dameware Mini Remote Control Unauthenticated RCE
Sep 30, 2019SolarWinds Dameware Mini Remote Control Unauthenticated RCE
Sep 30, 2019SolarWinds Dameware Mini Remote Control Unauthenticated RCE
Sep 30, 2019SolarWinds Dameware Mini Remote Control Unauthenticated RCE
Sep 30, 2019