PT-2019-18383 · Rdk · Rdk

Published

2019-06-20

·

Updated

2019-06-28

·

CVE-2019-6964

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RDK RDKB-20181217-1 CcspPandM module
Description A heap-based buffer over-read issue may allow attackers with login credentials to achieve information disclosure and code execution. This can be done by crafting an AJAX call responsible for DDNS configuration with an exactly 64-byte username, password, or domain, for which the buffer size is insufficient for the final '0' character. The issue is related to the CcspCommonLibrary and WebUI modules.
Recommendations For RDK RDKB-20181217-1 CcspPandM module, as a temporary workaround, consider restricting the length of the username, password, and domain variables to less than 64 bytes when making AJAX calls for DDNS configuration until a patch is available. Restrict access to the CcspPandM module to minimize the risk of exploitation.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6964

Affected Products

Rdk