PT-2022-9792 · Lanner · Lanner Inc Iac-Ast2500A

Andrea Palanca

·

Published

2022-10-24

·

Updated

2022-12-03

·

CVE-2021-26730

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lanner Inc IAC-AST2500A standard firmware version 1.10.0
Description A stack-based buffer overflow vulnerability in a subfunction of the Login handler func function of spx restservice allows an attacker to execute arbitrary code with the same privileges as the server user (root).
Recommendations For Lanner Inc IAC-AST2500A standard firmware version 1.10.0, consider disabling the Login handler func function until a patch is available to prevent exploitation of the buffer overflow vulnerability.

Fix

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2021-26730

Affected Products

Lanner Inc Iac-Ast2500A