8.8
CVE-2023-48221
- EPSS 0.89%
- Veröffentlicht 20.11.2023 18:15:06
- Zuletzt bearbeitet 21.11.2024 08:31:14
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
wire-avs provides Audio, Visual, and Signaling (AVS) functionality sure the secure messaging software Wire. Prior to versions 9.2.22 and 9.3.5, a remote format string vulnerability could potentially allow an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs 9.2.22 & 9.3.5 and is already included on all Wire products. No known workarounds are available.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wire ≫ Audio, Video, And Signaling Version < 9.2.22
Wire ≫ Audio, Video, And Signaling Version >= 9.3.0 <= 9.3.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.89% | 0.749 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| security-advisories@github.com | 7.3 | 1 | 5.8 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:H
|
CWE-134 Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.