peter bassill · operator
$ cve CVE-2018-6892 JSON

CVE-2018-6892 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 93.4% (pctl 100)

Patch early

A public exploit exists.

Description

An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing arbitrary code execution.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS93.39% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2018-02-11
Last modified2026-06-17

Affected (1)

VendorProduct
cloudmesync

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD