Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25436. PoCs published by Alessandro Magnosi.
AI-analyzed exploit summary This exploit demonstrates an arbitrary password change vulnerability in DeviceViewer 3.12.0.1 by leveraging a buffer overflow in the password change functionality. The PoC generates a malicious payload file that, when used as the 'old password,' bypasses authentication and allows setting a new password.
Description
Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to change passwords without proper validation of the old password field. Attackers can inject a large payload into the old password parameter during the change password process to bypass validation and set an arbitrary new password.
Exploits (1)
This exploit demonstrates an arbitrary password change vulnerability in DeviceViewer 3.12.0.1 by leveraging a buffer overflow in the password change functionality. The PoC generates a malicious payload file that, when used as the 'old password,' bypasses authentication and allows setting a new password.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N