CVE-2023-39435
Zavio IP Camera Stack-Based Buffer Overflow
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
08 nov 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321 IP Cameras
with firmware version M2.1.6.05 are
vulnerable to stack-based overflows. During the process of updating
certain settings sent from incoming network requests, the product does
not sufficiently check or validate allocated buffer size. This may lead
to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Zavio · IP Camera B8220Zavio · IP Camera B8520Zavio · IP Camera CB3211Zavio · IP Camera CB3212Zavio · IP Camera CB5220Zavio · IP Camera CB6231Zavio · IP Camera CD321Zavio · IP Camera CF7201Zavio · IP Camera CF7300Zavio · IP Camera CF7500Zavio · IP Camera CF7501¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →