📦

dameware_mini_remote_control

Vendor: solarwinds

Actively Exploited 0 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 0 Remote Access
Total CVEs 11 Total Indexed
Avg. EPSS 8.93% Exploit Prob.
Latest CVE CVE-2021-31217 Jul 13

Security Vulnerability Index

Page 1 / 2
9.1 CVSS

In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.

EPSS: 3.80%
9.8 CVSS
CVE-2019-3980
Exploit Found

The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.

EPSS: 5.18%
7.4 CVSS

Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.

EPSS: 25.59%
7.5 CVSS
CVE-2019-9017
Exploit Found

DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.

EPSS: 20.59%
7.8 CVSS
CVE-2018-12897
Exploit Found

SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.

EPSS: 1.67%
7.5 CVSS

Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link.

EPSS: 4.85%
5.0 CVSS

DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.

EPSS: 0.84%