9.8
CVE-2023-31475
- EPSS 23.68%
- Veröffentlicht 11.05.2023 11:15:09
- Zuletzt bearbeitet 27.01.2025 18:15:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gl-inet ≫ Gl-s20 Firmware Version < 3.216
Gl-inet ≫ Gl-x3000 Firmware Version < 3.216
Gl-inet ≫ Gl-mt3000 Firmware Version < 3.216
Gl-inet ≫ Gl-mt2500 Firmware Version < 3.216
Gl-inet ≫ Gl-mt2500a Firmware Version < 3.216
Gl-inet ≫ Gl-axt1800 Firmware Version < 3.216
Gl-inet ≫ Gl-a1300 Firmware Version < 3.216
Gl-inet ≫ Gl-ax1800 Firmware Version < 3.216
Gl-inet ≫ Gl-sft1200 Firmware Version < 3.216
Gl-inet ≫ Gl-mt1300 Firmware Version < 3.216
Gl-inet ≫ Gl-e750 Firmware Version < 3.216
Gl-inet ≫ Gl-mv1000 Firmware Version < 3.216
Gl-inet ≫ Gl-mv1000w Firmware Version < 3.216
Gl-inet ≫ Gl-s10 Firmware Version < 3.216
Gl-inet ≫ Gl-s200 Firmware Version < 3.216
Gl-inet ≫ Gl-s1300 Firmware Version < 3.216
Gl-inet ≫ Gl-sf1200 Firmware Version < 3.216
Gl-inet ≫ Gl-b1300 Firmware Version < 3.216
Gl-inet ≫ Gl-b2200 Firmware Version < 3.216
Gl-inet ≫ Gl-ap1300 Firmware Version < 3.216
Gl-inet ≫ Gl-ap1300lte Firmware Version < 3.216
Gl-inet ≫ Gl-x1200 Firmware Version < 3.216
Gl-inet ≫ Gl-x750 Firmware Version < 3.216
Gl-inet ≫ Gl-x300b Firmware Version < 3.216
Gl-inet ≫ Gl-xe300 Firmware Version < 3.216
Gl-inet ≫ Gl-ar750s Firmware Version < 3.216
Gl-inet ≫ Gl-ar750 Firmware Version < 3.216
Gl-inet ≫ Gl-mifi Firmware Version < 3.216
Gl-inet ≫ Gl-mt300n-v2 Firmware Version < 3.216
Gl-inet ≫ Gl-ar300m Firmware Version < 3.216
Gl-inet ≫ Gl-usb150 Firmware Version < 3.216
Gl-inet ≫ Microuter-n300 Firmware Version < 3.216
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 23.68% | 0.959 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9 | 2.2 | 6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.