← back
CVE-2024-0962

obgm libcoap Configuration File coap_oscore.c get_split_entry stack-based overflow

CVSS 6.3 MEDIUMEPSS 0.8%CWE-121
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.3EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
27 Jan 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. Affected by this issue is the function get_split_entry of the file src/coap_oscore.c of the component Configuration File Handler. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-252206 is the identifier assigned to this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Affected products
obgm · libcoap