CVE-2019-3980

CRITICAL EXPLOITED

Solarwinds Dameware Mini Remote Control - Origin Validation Error

Title source: rule

Description

The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.

Exploits (4)

nomisec WORKING POC 18 stars
by warferik · remote-auth
https://github.com/warferik/CVE-2019-3980
nomisec WORKING POC 2 stars
by Barbarisch · remote
https://github.com/Barbarisch/CVE-2019-3980
nomisec WORKING POC 1 stars
by CyberQuestor-infosec · remote
https://github.com/CyberQuestor-infosec/CVE-2019-3980-Open_Net_Admin_v18.1.1_RCE
nomisec WORKING POC
by boydhacks · poc
https://github.com/boydhacks/dameflare

Scores

CVSS v3 9.8
EPSS 0.4091
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2025-01-28

Classification

CWE
CWE-346
Status published

Affected Products (1)

solarwinds/dameware_mini_remote_control

Timeline

Published Oct 08, 2019
Tracked Since Feb 18, 2026