---
id: CVE-2019-25597
title: >-
  NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor
  Community field that allows local attackers to crash the application by
  supplying an excessively long string
summary: >-
  NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor
  Community field that allows local attackers to crash the application by
  supplying an excessively long string. Attackers can paste a large payload into
  the Com…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-787
vendor: nsasoft
product: nsauditor
affected:
  - 'nsauditor >= 3.1.2.0, < 3.2.7'
patched:
  - nsauditor 3.2.7
published: '2026-03-22'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T08:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25597'
references:
  - url: 'http://www.nsauditor.com/downloads/nsauditor_setup.exe'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/46757'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nsauditor-denial-of-service-via-community-field
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00238
epssPercentile: 0.13529
ingestedAt: '2026-10-07T08:20:03.905Z'
---

## Overview

NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a large payload into the Community field and trigger the Walk function to cause a denial of service condition.

## Affected

- `nsauditor >= 3.1.2.0, < 3.2.7`

## Remediation

Upgrade past the affected range:

- `nsauditor 3.2.7`
