PT-2019-18383 · Rdk · Rdk
Publicado
2019-06-20
·
Atualizado
2019-06-28
·
CVE-2019-6964
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RDK RDKB-20181217-1 CcspPandM module
Description
A heap-based buffer over-read issue may allow attackers with login credentials to achieve information disclosure and code execution. This can be done by crafting an AJAX call responsible for DDNS configuration with an exactly 64-byte
username, password, or domain, for which the buffer size is insufficient for the final '0' character. The issue is related to the CcspCommonLibrary and WebUI modules.Recommendations
For RDK RDKB-20181217-1 CcspPandM module, as a temporary workaround, consider restricting the length of the
username, password, and domain variables to less than 64 bytes when making AJAX calls for DDNS configuration until a patch is available. Restrict access to the CcspPandM module to minimize the risk of exploitation.Correção
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Rdk