PT-2021-14827 · Unknown · Ic Module Cma

Matt Wiseman

·

Published

2021-12-22

·

Updated

2022-08-31

·

CVE-2021-21901

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iC Module CMA version 5.0
Description A stack-based buffer overflow issue exists in the CMA check udp crc function. This can be triggered by a specially-crafted packet, leading to a buffer overflow during a call to memcpy. An attacker can exploit this by sending a malicious packet.
Recommendations For version 5.0, consider disabling the check udp crc function as a temporary workaround until a patch is available. Restrict access to the vulnerable function to minimize the risk of exploitation. Avoid using the memcpy call in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2021-21901

Affected Products

Ic Module Cma