PT-2024-31452 · Unknown · Uci Idol 2

Ludwig Stage

+1

·

Published

2024-08-21

·

Updated

2024-08-26

·

CVE-2024-45169

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UCI IDOL 2 versions through 2.12
Description An issue was discovered in UCI IDOL 2 due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer. This makes IDOL2 vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution via the xB0x00x3c byte sequence.
Recommendations For versions through 2.12, consider disabling the functionality that allows deserialization of user-input data until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using the vulnerable byte sequence xB0x00x3c in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-45169

Affected Products

Uci Idol 2