CVE-2018-25225Disclosure(sipp_project / sipp)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the return address and executing arbitrary code through return-oriented programming gadgets.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sipp

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-28); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
sipp

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-28: 3Mentions · 2026-03-29: 1Technical Details · 2026-03-28: 303-2803-29
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-283
Disclosure2General1
2026-03-291
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2018-25225 SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in th… https://www.cve.org/CVERecord?id=CVE-2018-25225

    Post summary

    The text announces the existence of CVE‑2018‑25225, describing a stack‑based buffer overflow in SIPP 3.3 that allows local code execution by unauthenticated actors, with no mention of PoC, exploitation, or mitigation.

    0001039
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2018-25225 📊 Severity: 8.4 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2018-25225 #CVE-2018-25225 #CVE #High #CyberSecurity #InfoSec https://t.co/YTy1jYlyIp

    Post summary

    The tweet simply announces CVE-2018-25225 with a severity score of 8.4, pointing to the NVD page, but does not provide additional technical details or remediation advice.

    0000024
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2018-25225 - SIPP 3.3 Stack-Based Buffer Overflow via Configuration File Intel Report: https://ift.tt/x19jcdt

    Post summary

    This alert highlights the CVE-2018-25225 stack-based buffer overflow in SIPP 3.3, but does not mention a PoC, exploit code, active use, or patch.

    0000026
    283 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2018-25225: HIGH] SIPP 3.3 presents a critical buffer overflow vulnerability allowing local attackers to execute arbitrary code by manipulating the configuration file. #CyberSecurity#cve,CVE-2018-25225,#cybersecurity https://cvefind.com/CVE-2018-25225

    Post summary

    The tweet discloses a critical buffer overflow issue (CVE‑2018‑25225) in SIPP 3.3 that could allow local attackers to execute arbitrary code via the configuration file.

    0000035
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsipp_projectsipp3.3--

Explore more