PT-2021-3973 · Hcc · Hcc Embedded Interniche
Published
2021-05-28
·
Updated
2021-08-26
·
CVE-2021-31226
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HCC embedded InterNiche version 4.0.1
Description
A potential heap buffer overflow exists in the code that parses the HTTP POST request due to a lack of size validation. This issue requires an attacker to send a crafted HTTP POST request with a URI longer than 50 bytes, leading to a heap overflow in
wbs post() via an strcpy() call. The vulnerability may allow a remote attacker to execute arbitrary code by exploiting errors in HTTP request handling.Recommendations
For HCC embedded InterNiche version 4.0.1, consider disabling the
wbs post() function as a temporary workaround until a patch is available. Restrict access to the HTTP POST request handling module to minimize the risk of exploitation. Avoid using URIs longer than 50 bytes in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Heap Based Buffer Overflow
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hcc Embedded Interniche