Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 30 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lakesidesoftware
Lakesidesoftware systrack Agent |
|
| Vendors & Products |
Lakesidesoftware
Lakesidesoftware systrack Agent |
Fri, 29 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially crafted UDP packet. Attackers can send a malformed packet with an invalid memory address at offset 0x4 in the payload to trigger an access violation and cause a denial of service. | |
| Title | Lakeside SysTrack Agent LsiAgent.exe Out-of-Bounds Read via UDP | |
| Weaknesses | CWE-125 CWE-754 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-29T19:07:28.014Z
Reserved: 2026-04-07T20:57:06.210Z
Link: CVE-2026-39929
Updated: 2026-05-29T19:07:18.906Z
Status : Awaiting Analysis
Published: 2026-05-28T22:16:58.693
Modified: 2026-06-01T16:52:20.117
Link: CVE-2026-39929
No data.
OpenCVE Enrichment
Updated: 2026-06-18T13:00:16Z