CVE-2019-8275: Siemens Sinumerik Access mymachine/p2p
Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.
UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being accessed by remote users. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
Affected products
- Siemens Sinumerik Access mymachine/p2p: before 4.8 (fixed in 4.8)
- Siemens Sinumerik Pcu Base WIN10 Software/ipc: before 14.00 (fixed in 14.00)
- Siemens Sinumerik Pcu Base WIN7 Software/ipc: up to and including 12.01
- Uvnc Ultravnc: before 1.2.2.3 (fixed in 1.2.2.3)
Published 2019-03-08. Last modified 2026-06-17.