CVE-2012-2944: Networkupstools Nut

High severity, CVSS 7.5. EPSS: 6.2% chance of exploitation in the next 30 days.

Buffer overflow in the addchar function in common/parseconf.c in upsd in Network UPS Tools (NUT) before 2.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (electric-power outage) via a long string containing non-printable characters.

Affected products

  • Networkupstools Nut: up to and including 2.6.3-3; version 2.4.2 only; version 2.4.3 only; version 2.6.0 only; version 2.6.0-1 only; version 2.6.1 only; …

Published 2012-06-01. Last modified 2026-06-16.