CVE Database
/

CVE-2026-39929

Back to search

CVE-2026-39929

Published: May 28, 2026

Modified: May 29, 2026

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially crafted UDP packet. Attackers can send a malformed packet with an invalid memory address at offset 0x4 in the payload to trigger an access violation and cause a denial of service.

VendorProductVersions

Lakeside Software, LLC.

SysTrack Agent

affected
0 - < 11.2.1.28
affected
11.3.0.xxx - < 11.3.0.38
affected
11.4.0.xxx - < 11.4.0.24
affected
11.5.0.xxx - < 11.5.0.15

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now