PT-2019-18383 · Rdk · Rdk

Publicado

2019-06-20

·

Atualizado

2019-06-28

·

CVE-2019-6964

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RDK RDKB-20181217-1 CcspPandM module
Description A heap-based buffer over-read issue may allow attackers with login credentials to achieve information disclosure and code execution. This can be done by crafting an AJAX call responsible for DDNS configuration with an exactly 64-byte username, password, or domain, for which the buffer size is insufficient for the final '0' character. The issue is related to the CcspCommonLibrary and WebUI modules.
Recommendations For RDK RDKB-20181217-1 CcspPandM module, as a temporary workaround, consider restricting the length of the username, password, and domain variables to less than 64 bytes when making AJAX calls for DDNS configuration until a patch is available. Restrict access to the CcspPandM module to minimize the risk of exploitation.

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-6964

Produtos afetados

Rdk