6.5
CVE-2026-23570
- EPSS 0.06%
- Veröffentlicht 29.01.2026 08:50:52
- Zuletzt bearbeitet 11.02.2026 20:17:17
- Quelle psirt@teamviewer.com
- CVE-Watchlists
- Unerledigt
A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sync command. This could result in forged or nonsensical datetime prefixes and compromising log integrity and forensic correlation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Teamviewer ≫ Digital Employee Experience Version < 26.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.189 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@teamviewer.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.