CVE-2019-8276

HIGH

UltraVNC < 1.2.2.3 - Denial of Service via File Transfer Request Handler

Title source: llm
STIX 2.1

Description

UltraVNC revision 1211 has a stack buffer overflow vulnerability in VNC server code inside file transfer request handler, which can result in Denial of Service (DoS). This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1212.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-927095.pdf
Third Party Advisory, US Government Resource x_refsource_misc
https://www.us-cert.gov/ics/advisories/icsa-20-161-06

Scores

CVSS v3 7.5
EPSS 0.0073
EPSS Percentile 72.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-121 CWE-787
Status published
Products (4)
siemens/sinumerik_access_mymachine\/p2p < 4.8
siemens/sinumerik_pcu_base_win10_software\/ipc < 14.00
siemens/sinumerik_pcu_base_win7_software\/ipc < 12.01
uvnc/ultravnc < 1.2.2.3
Published Mar 08, 2019
Tracked Since Feb 18, 2026