CVE-2010-4840 - CVE House
Back to Database
Status published High CVE-2010-4840

Multiple buffer overflows in the Syslog server in ManageEngine EventLog...

Vulnerability Description

Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.exe process crash) or possibly execute arbitrary code via a long Syslog PRI message header to UDP port (1) 513 or (2) 514. Fixed in 7.2 Build 7020.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-4840

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

manageengine

View all reports →

Affected Software

eventlog analyzer
Vulnerable Versions:
6.1

Timeline

Official Publish: September 27th, 2011
Last Modified: August 7th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.