9.8
CVE-2023-43755
- EPSS 1.26%
- Veröffentlicht 08.11.2023 23:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:43
- Erkennungen
Zavio IP Camera Stack-Based Buffer Overflow
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. During the processing and parsing of certain fields in XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zavio ≫ Cf7500 Firmware Version m2.1.6.05
Zavio ≫ Cf7300 Firmware Version m2.1.6.05
Zavio ≫ Cf7201 Firmware Version m2.1.6.05
Zavio ≫ Cf7501 Firmware Version m2.1.6.05
Zavio ≫ Cb3211 Firmware Version m2.1.6.05
Zavio ≫ Cb3212 Firmware Version m2.1.6.05
Zavio ≫ Cb5220 Firmware Version m2.1.6.05
Zavio ≫ Cb6231 Firmware Version m2.1.6.05
Zavio ≫ B8520 Firmware Version m2.1.6.05
Zavio ≫ B8220 Firmware Version m2.1.6.05
Zavio ≫ Cd321 Firmware Version m2.1.6.05
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.26% | 0.657 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| DHS.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-121 Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03