9.8
CVE-2024-50694
- EPSS 0.33%
- Veröffentlicht 24.01.2025 23:15:09
- Zuletzt bearbeitet 29.05.2025 16:02:20
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the underlying code does not check the bounds of the buffer that is used to store the message. This may lead to a stack-based buffer overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sungrowpower ≫ Winet-s Firmware Version < 200.001.00.p027
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.558 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-121 Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).