CVE-2019-8268: Siemens Sinumerik Access mymachine/p2p
Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.
UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadString function, which can potentially result code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1207.
Affected products
- Siemens Sinumerik Access mymachine/p2p: before 4.8 (fixed in 4.8)
- Siemens Sinumerik Pcu Base WIN10 Software/ipc: before 14.00 (fixed in 14.00)
- Siemens Sinumerik Pcu Base WIN7 Software/ipc: up to and including 12.01
- Uvnc Ultravnc: before 1.2.2.3 (fixed in 1.2.2.3)
Published 2019-03-08. Last modified 2026-06-17.