PT-2022-6233 · Netcomm · Netcomm Nf20Mesh+2

Published

2022-11-11

·

Updated

2023-01-19

·

CVE-2022-4873

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Netcomm NF20MESH versions Netcomm NF20 versions Netcomm NL1902 versions
Description A stack-based buffer overflow issue affects the sessionKey parameter, allowing a remote attacker to potentially execute arbitrary code by providing a specific number of bytes, which overwrites the instruction pointer on the stack and crashes the application at a known location.
Recommendations For Netcomm NF20MESH, consider disabling the sessionKey parameter until a patch is available. For Netcomm NF20, restrict access to the vulnerable module to minimize the risk of exploitation. For Netcomm NL1902, avoid using the sessionKey parameter in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Improper Authentication

Stack Overflow

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

BDU:2023-00600
BDU:2023-00608
CVE-2022-4873

Affected Products

Netcomm Nf20
Netcomm Nf20Mesh
Netcomm Nl1902