PT-2021-3973 · Hcc · Hcc Embedded Interniche

Published

2021-05-28

·

Updated

2021-08-26

·

CVE-2021-31226

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HCC embedded InterNiche version 4.0.1
Description A potential heap buffer overflow exists in the code that parses the HTTP POST request due to a lack of size validation. This issue requires an attacker to send a crafted HTTP POST request with a URI longer than 50 bytes, leading to a heap overflow in wbs post() via an strcpy() call. The vulnerability may allow a remote attacker to execute arbitrary code by exploiting errors in HTTP request handling.
Recommendations For HCC embedded InterNiche version 4.0.1, consider disabling the wbs post() function as a temporary workaround until a patch is available. Restrict access to the HTTP POST request handling module to minimize the risk of exploitation. Avoid using URIs longer than 50 bytes in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04492
CVE-2021-31226

Affected Products

Hcc Embedded Interniche