PT-2023-5378 · D Link · Di-7200Gv2.E1

CVE-2023-43197

·

Publicado

2023-07-10

·

Atualizado

2023-09-22

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link device DI-7200GV2.E1 version 21.04.09E1
Description The issue is related to a stack overflow in the tgfile.asp function when processing the fn parameter. This can allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The tgfile.asp function is vulnerable due to a buffer overflow in memory when handling the fn parameter.
Recommendations For D-Link device DI-7200GV2.E1 version 21.04.09E1, consider disabling the tgfile.asp function or restricting access to it until a patch is available. Avoid using the fn parameter in the affected function to minimize the risk of exploitation.

Exploit

Correção

Stack Overflow

Memory Corruption

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06006
CVE-2023-43197

Produtos afetados

Di-7200Gv2.E1