A stack-based buffer overflow exists in the Syslog service (nssyslogd.exe) of Enterasys Network Management Suite (NMS) prior to version 4.1.0.80. The vulnerability is triggered by sending a specially crafted syslog message with an overly long PRIO field to UDP port 514, resulting in a buffer overflow condition that can be exploited for remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (Ruby file) that exploits a stack buffer overflow vulnerability (CVE-2011-5227) in the Enterasys NetSight nssyslogd.exe service. The exploit targets the syslog UDP service (port 514) on Windows XP SP3 and Windows 2003 SP2 systems running NetSight 4.0.1.34. The module crafts a malicious syslog message with a specially crafted PRIO field to trigger the overflow, allowing arbitrary code execution with SYSTEM privileges. The payload is customizable via Metasploit and can be any supported shellcode. The exploit includes specific ROP chains and stack pivots for each supported Windows version. The only fingerprintable endpoints are the UDP port 514 and the nssyslogd.exe service. The code is operational and ready for use within the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.