Lucene search

K
cveMitreCVE-2023-26257
HistoryFeb 27, 2023 - 5:15 a.m.

CVE-2023-26257

2023-02-2705:15:12
CWE-401
mitre
web.nvd.nist.gov
34
covesa
connected vehicle systems alliance
dlt-daemon
cve-2023-26257
memory allocation
security vulnerability
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

43.6%

An issue was discovered in the Connected Vehicle Systems Alliance (COVESA; formerly GENIVI) dlt-daemon through 2.18.8. Dynamic memory is not released after it is allocated in dlt-control-common.c.

Affected configurations

Nvd
Node
covesadlt-daemonRange2.18.8
VendorProductVersionCPE
covesadlt-daemon*cpe:2.3:a:covesa:dlt-daemon:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

43.6%