PT-2016-7515 · Libcsp · Libcsp

Published

2016-10-28

·

Updated

2025-08-14

·

CVE-2016-8597

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libcsp library versions 1.4 and earlier
Description The issue is related to a buffer overflow in the csp sfp recv fp function in csp sfp.c. This allows hostile components with network access to the SFP underlying network layers to execute arbitrary code via specially crafted SFP packets.
Recommendations For libcsp library versions 1.4 and earlier, consider applying a patch or fix to address the buffer overflow issue in the csp sfp recv fp function. As a temporary workaround, restrict access to the SFP underlying network layers to minimize the risk of exploitation.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2016-8597

Affected Products

Libcsp