CVE-2026-3437
An improper restriction of operations within the bounds of a memory buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could result in escalation of privileges or cause a denial-of-service condition.
- Affected products
- Portwell Engineering Toolkits
- Portwell Engineering Toolkits
- = 4.8.2
- CVSS 4.0
- 9.3 CRITICAL
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.2% (5th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2026-03-03
Fix
Remediation Status: - Affected: Portwell Engineering Toolkits Version 4.8.2 and earlier - Fixed Version: Portwell Engineering Toolkits version [v5.0.0]
CVE-2026-3437 at NVD
2 known exploits for CVE-2026-3437
Proof-of-concept code and exploit modules indexed by Sploitus