CVE-2017-12786: Noviflow Noviware

Critical severity, CVSS 9.8. EPSS: 25.3% chance of exploitation in the next 30 days.

Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when ACL modifications are applied. This could be leveraged by remote, unauthenticated attackers to gain resultant privileged (root) code execution on the switch, because there is a stack-based buffer overflow during unserialization of packet data.

Affected products

  • Noviflow Noviware: up to and including 400.2.6

Published 2017-08-22. Last modified 2026-06-17.