CVE-2018-9115 EXPLOIT
5.3
MEDIUM · CVSS 3.0 · EPSS 5.8% (pctl 93)
Patch early
A public exploit exists.
Description
Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG interface. An attacker can freeze the Situational Layer, which means that the Situational Picture is no longer updated. Unfortunately, the user cannot notice until he tries to work with that layer.
Scoring
| CVSS | 5.3 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| EPSS | 5.79% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-04-04 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| systematicinc | sitaware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Systematic SitAware - NVG Denial of Service | 2018-03-30 |
References
→ the Explorer · watch your stack · NVD