CVE-2019-17424

HIGH

Nipper-ng - Out-of-Bounds Write

Title source: rule

Description

A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Execution or Denial Of Service via a crafted file.

Exploits (3)

exploitdb WORKING POC
by Guy Levin · pythonremotelinux
https://www.exploit-db.com/exploits/47673
nomisec WORKING POC 5 stars
by mavlevin · poc
https://github.com/mavlevin/CVE-2019-17424
inthewild WORKING POC
poc
https://github.com/guywhataguy/cve-2019-17424

Scores

CVSS v3 7.8
EPSS 0.2837
EPSS Percentile 96.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
nipper-ng_project/nipper-ng 0.11.10
Published Oct 22, 2019
Tracked Since Feb 18, 2026