{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-28T07:17:12.906","vulnerabilities":[{"cve":{"id":"CVE-2019-3955","sourceIdentifier":"vulnreport@tenable.com","published":"2019-06-07T20:29:01.467","lastModified":"2026-06-17T02:35:56.957","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Dameware Remote Mini Control version 12.1.0.34 and prior contains a unauthenticated remote heap overflow due to the server not properly validating RsaPubKeyLen during key negotiation. An unauthenticated remote attacker can cause a heap buffer overflow by specifying a large RsaPubKeyLen, which could cause a denial of service."},{"lang":"es","value":"Dameware Remote Mini Control versión 12.1.0.34 y anterior, contiene un desbordamiento remoto de pila no autenticado, debido a que el servidor no está comprobando correctamente RsaPubKeyLen durante la negociación de la clave. Un atacante remoto no autenticado puede causar un desbordamiento de búfer de la pila especificando un parámetro largo RsaPubKeyLen, lo que podría causar una denegación de servicio."}],"affected":[{"source":"vulnreport@tenable.com","affectedData":[{"vendor":"n/a","product":"Solarwinds Dameware Remote Mini Controller","versions":[{"version":"All versions prior to version 12.1.0.34","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:dameware:remote_mini_control:*:*:*:*:*:*:*:*","versionEndIncluding":"12.1.0.34","matchCriteriaId":"88EFD339-8C6D-43F7-84E1-84626579BE25"}]}]}],"references":[{"url":"https://www.tenable.com/security/research/tra-2019-26","source":"vulnreport@tenable.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.tenable.com/security/research/tra-2019-26","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}