PT-2023-7358 · Dreamsecurity · Dreamsecurity Magicline4Nx
Han Myung-Wook
+2
·
Published
2023-03-21
·
Updated
2023-11-07
·
CVE-2023-45797
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DreamSecurity MagicLine4NX versions 1.0.0.1 through 1.0.0.26
Description
The issue is related to a buffer overflow vulnerability. This vulnerability can be exploited by a remote attacker to gain unauthorized access to protected information and potentially conduct a "Watering Hole" attack. The vulnerability allows an attacker to remotely execute code. There have been reports of a North Korean government-sponsored hacking group exploiting this vulnerability to install malware.
Recommendations
For DreamSecurity MagicLine4NX versions 1.0.0.1 through 1.0.0.26, update to a version that contains a fix for this vulnerability.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dreamsecurity Magicline4Nx