CVE 6.5 MEDIUM

Log timestamp tampering vulnerability in Content Distribution Service_CVE-2026-23570

6.5 / 10
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Description

A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sync command. This could result in forged or nonsensical datetime prefixes and compromising log integrity and forensic correlation.

Basic Information

ID CVE-2026-23570
Source TV
Published Jan 29, 2026 at 08:50

Affected Product

Vendor TeamViewer
Product DEX
Affected Versions TeamViewer DEX 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.