PT-2023-6771 · Zavio · Zavio Cb3211+10

Attila Szasz

+1

·

Publicado

2023-10-31

·

Atualizado

2024-08-02

·

CVE-2023-43755

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 version M2.1.6.05
Description The issue is caused by stack-based overflows during the processing and parsing of certain fields in XML elements from incoming network requests. The product does not sufficiently check or validate allocated buffer size, which may lead to remote code execution. This can be exploited by a remote attacker to execute arbitrary code.
Recommendations For Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 version M2.1.6.05, update the firmware to a version that fixes the stack-based overflow vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07579
CVE-2023-43755

Produtos afetados

Zavio B8220
Zavio B8520
Zavio Cb3211
Zavio Cb3212
Zavio Cb5220
Zavio Cb6231
Zavio Cd321
Zavio Cf7201
Zavio Cf7300
Zavio Cf7500
Zavio Cf7501