peter bassill · operator
$ cve CVE-2018-10388 JSON

CVE-2018-10388

9.8
CRITICAL · CVSS 3.1 · EPSS 4.4% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.36% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-134
On CISA KEVno
Public exploitnone known
Published2019-12-23
Last modified2026-06-17

Affected (1)

VendorProduct
open tftp server projectopen tftp server

References

→ the Explorer  ·  watch your stack  ·  NVD