PT-2024-38351 · Vivotek · Vivotek Sd9364

Jylsec

·

Published

2024-08-03

·

Updated

2024-08-13

·

CVE-2024-7441

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vivotek SD9364 VVTK-0103f (affected versions not specified)
Description A critical vulnerability affects the httpd component, specifically the read function. The manipulation of the Content-Length argument leads to a stack-based buffer overflow. This issue can be exploited remotely. The exploit has been publicly disclosed. It is noted that this vulnerability only affects products that are no longer supported by the maintainer, and the vendor has confirmed the affected release tree is end-of-life.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-7441

Affected Products

Vivotek Sd9364