CVE-2019-10060

HIGH

Verix Multi-app Conductor <2.7 - Buffer Overflow

Title source: llm
STIX 2.1

Description

The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configuration key value. An attacker must be able to download files to the device in order to exploit this vulnerability.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0139
EPSS Percentile 80.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
verifone/verix_multi-app_conductor 2.7
Published Mar 26, 2019
Tracked Since Feb 18, 2026