CVE-2019-10060: Verifone Verix Multi-App Conductor

High severity, CVSS 8.1. EPSS: 1.7% chance of exploitation in the next 30 days.

The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configuration key value. An attacker must be able to download files to the device in order to exploit this vulnerability.

Affected products

  • Verifone Verix Multi-App Conductor: version 2.7 only

Published 2019-03-26. Last modified 2026-06-17.