Dameware's vulnerability footprint centers on its remote-control and mini-remote-control products, which serve system administrators for remote systems management and troubleshooting across enterprise environments. The observed weakness classes—improper input validation, memory-buffer boundary violations, and out-of-bounds read/write conditions—reflect the memory-safety and input-handling demands of client-side remote-access software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dameware over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2345CRITICAL Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbitrary code via a crafted string | Mar 17, 2016 | 9.8 | 71 | NO | YES |
CVE-2019-3955HIGH Dameware Remote Mini Control version 12.1.0.34 and prior contains a unauthenticated remote heap overflow due to the server not properly validating RsaPubKeyLen during key negotiati | Jun 7, 2019 | 7.5 | 34 | NO | NO |
CVE-2019-3956HIGH Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating CltDHPubKeyLen during key neg | Jun 7, 2019 | 7.4 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dameware.
Media articles that mention a CVE ID that affects a product developed by Dameware — matched by CVE ID, not by vendor name.