PT-2021-14827 · Unknown · Ic Module Cma
Matt Wiseman
·
Published
2021-12-22
·
Updated
2022-08-31
·
CVE-2021-21901
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
iC Module CMA version 5.0
Description
A stack-based buffer overflow issue exists in the CMA
check udp crc function. This can be triggered by a specially-crafted packet, leading to a buffer overflow during a call to memcpy. An attacker can exploit this by sending a malicious packet.Recommendations
For version 5.0, consider disabling the
check udp crc function as a temporary workaround until a patch is available. Restrict access to the vulnerable function to minimize the risk of exploitation. Avoid using the memcpy call in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ic Module Cma