CloudView NMS before 2.10a has a format string issue exploitable over SNMP.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/98723 | vdb entry |
https://community.rapid7.com/community/infosec/blog/2016/09/07/multiple-disclosures-for-multiple-network-management-systems-part-2 | third party advisory exploit technical description |