peter bassill · operator
$ cve CVE-2017-13696 JSON

CVE-2017-13696

9.8
CRITICAL · CVSS 3.0 · EPSS 78.3% (pctl 100)

Patch early

EPSS 78.3% — above the 10% action threshold.

Description

A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server component. Successful exploitation of the software will allow an attacker to gain complete access to the system with NT AUTHORITY / SYSTEM level privileges. The vulnerability lies due to improper handling and sanitization of the incoming request.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS78.31% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2018-01-24
Last modified2026-06-17

Affected (4)

VendorProduct
flexensediskpulse
flexensedisksavvy
flexensedupscout
flexensesyncbreeze

References

→ the Explorer  ·  watch your stack  ·  NVD