CVE-2019-10060
Last modified
CVE-2019-10060 is a vulnerability of currently unknown severity. The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configuration key value. An attacker must be able to download files to the device in order to exploit this vulnerability.. EPSS estimates a 1.68% chance of exploitation in the next 30 days.
Description
The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configuration key value. An attacker must be able to download files to the device in order to exploit this vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Verifone | Verix Multi-App Conductor | 2.7 |
References
- https://github.com/VerSprite/research/blob/master/advisories/VS-2019-002.mdThird Party Advisory
- https://github.com/VerSprite/research/blob/master/advisories/VS-2019-002.mdThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10060?
How severe is CVE-2019-10060?
How do I fix CVE-2019-10060?
Are you affected by CVE-2019-10060?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
