← Vulnerability feed

Vulnerability record · CVE-2008-5159 · published 18 November 2008

CVE-2008-5159: WinCom LPD Total remote admin protocol integer overflow

CClientsoftware · Wincome Mpd Total

WinCom LPD Total 3.0.2.623 and earlier mishandles a large string length argument in its remote administration protocol processing, causing an integer overflow that leads to memory corruption. The flaw is remotely reachable over the network without authentication, so any exposed LPD administration service is at risk.

10.0 CVSS 2.0 High EPSS 60% · top 0.9% CWE-189 · CWE-189
10.0CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to cause a denial of service (crash) via a large string length argument, which triggers memory corruption.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote memory corruption with a public proof of concept and very high EPSS, though impact is documented only as denial of service.

What it is

WinCom LPD Total 3.0.2.623 and earlier mishandles a large string length argument in its remote administration protocol processing, causing an integer overflow that leads to memory corruption. The flaw is remotely reachable over the network without authentication, so any exposed LPD administration service is at risk.

Impact

An attacker can crash the service, causing a denial of service. The CVSS vector claims full confidentiality, integrity and availability impact, but the description only demonstrates memory corruption and a crash, so code execution is not confirmed by the record.

Attack surface

Reached over the network via the remote administration protocol (AV:N, AC:L, Au:N). No authentication or user interaction is required per the vector and description.

Exploitation

Not listed in CISA KEV and no ransomware association. EPSS is high at roughly 0.597 (99th percentile), and public references include an advisory and a proof-of-concept archive, indicating exploit code is publicly available.

What to do

  • Upgrade WinCom LPD Total past 3.0.2.623 or apply the vendor fix referenced in the Secunia advisory.
  • Restrict network access to the remote administration protocol to trusted management hosts only.
  • Block or firewall the administration port from untrusted networks and the internet.
  • Monitor the vendor for an updated release if no fixed version is documented.

Detection

  • Alert on LPD administration service crashes or unexpected process termination.
  • Inspect network traffic to the admin protocol for oversized length fields or malformed strings.
  • Correlate repeated connection attempts to the admin port from single sources with crash events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-5159 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2008-5159), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.