CVE-2019-15878
CVE-2019-15878
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
13 May 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-free situation due to improper checking in SCTP when an application tries to update an SCTP-AUTH shared key.
Affected products
n/a · FreeBSDWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →