CVE-2018-10388
9.8
CRITICAL · CVSS 3.1 · EPSS 4.4% (pctl 91)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.36% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-134 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-12-23 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| open tftp server project | open tftp server |
References
→ the Explorer · watch your stack · NVD