CVE-2018-6892: Cloudme Sync
Critical severity, CVSS 9.8. EPSS: 93.4% chance of exploitation in the next 30 days.
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing arbitrary code execution.
Affected products
- Cloudme Sync: up to and including 1.10.9
Published 2018-02-11. Last modified 2026-06-17.