CVE-2023-38562 - CERT CVE
ID CVE-2023-38562
Sažetak A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.
Reference
CVSS
Base: 8.7
Impact: 5.8
Exploitability:2.2
Pristup
VektorSloženostAutentikacija
NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE HIGH HIGH
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
Zadnje važnije ažuriranje 12-02-2025 - 18:51
Objavljeno 20-02-2024 - 15:15