ZeroHour

CVE-2019-10060

CVSS 3.0
8.1 high
EPSS
2%p76
Published
()
Modified
Description

The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configuration key value. An attacker must be able to download files to the device in order to exploit this vulnerability.

Vendors
verifone
Products
verix multi-app conductor
Weakness
CWE-119
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.