PT-2024-38349 · Vivotek · Vivotek Cc8160

Jylsec

·

Published

2024-08-03

·

Updated

2024-08-13

·

CVE-2024-7439

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vivotek CC8160 VVTK-0100d (affected versions not specified)
Description A critical vulnerability was found in the httpd component, specifically in the function read. The manipulation of the argument Content-Length leads to a stack-based buffer overflow. This issue can be exploited remotely. The exploit has been disclosed to the public. It is noted that this vulnerability only affects products that are no longer supported by the maintainer, and the vendor has confirmed that the affected release tree is end-of-life.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-7439

Affected Products

Vivotek Cc8160