Back

CVE-2017-13696

CRITICAL

A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server component. Successful exploitation of the software will allow an attacker to gain complete access to the system with NT AUTHORITY / SYSTEM level privileges. The vulnerability lies due to improper handling and sanitization of the incoming request.

Published: Jan 24, 2018 Modified: Jun 17, 2026
CWE-119

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
flexense dupscout 9.9.14
flexense disksavvy 9.9.14
flexense syncbreeze 9.9.16
flexense diskpulse 9.9.16

GitHub Security Advisory GHSA-pw6x-q52c-69f8

A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14,...

References (10)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 79.35%

Top 0% most likely to be exploited

Threat Score 73 / 100

Data Sources

NVD EPSS GitHub