Lucene search

K
cve[email protected]CVE-2023-39435
HistoryNov 08, 2023 - 11:15 p.m.

CVE-2023-39435

2023-11-0823:15:08
CWE-121
CWE-787
web.nvd.nist.gov
19
cve-2023-39435
zavio
ip cameras
stack-based overflow
firmware vulnerability
remote code execution
nvd

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.1%

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321 IP Cameras

with firmware version M2.1.6.05 are
vulnerable to stack-based overflows. During the process of updating
certain settings sent from incoming network requests, the product does
not sufficiently check or validate allocated buffer size. This may lead
to remote code execution.

Affected configurations

NVD
Node
zaviocf7500Match-
AND
zaviocf7500_firmwareMatchm2.1.6.05
Node
zaviocf7300Match-
AND
zaviocf7300_firmwareMatchm2.1.6.05
Node
zaviocf7201Match-
AND
zaviocf7201_firmwareMatchm2.1.6.05
Node
zaviocf7501Match-
AND
zaviocf7501_firmwareMatchm2.1.6.05
Node
zaviocb3211Match-
AND
zaviocb3211_firmwareMatchm2.1.6.05
Node
zaviocb3212Match-
AND
zaviocb3212_firmwareMatchm2.1.6.05
Node
zaviocb5220Match-
AND
zaviocb5220_firmwareMatchm2.1.6.05
Node
zaviocb6231Match-
AND
zaviocb6231_firmwareMatchm2.1.6.05
Node
zaviob8520_firmwareMatchm2.1.6.05
AND
zaviob8520Match-
Node
zaviob8220_firmwareMatchm2.1.6.05
AND
zaviob8220Match-
Node
zaviocd321_firmwareMatchm2.1.6.05
AND
zaviocd321Match-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "IP Camera CF7500",
    "vendor": "Zavio",
    "versions": [
      {
        "status": "affected",
        "version": "version M2.1.6.05"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "IP Camera CF7300",
    "vendor": "Zavio",
    "versions": [
      {
        "status": "affected",
        "version": "version M2.1.6.05"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "IP Camera CF7201",
    "vendor": "Zavio",
    "versions": [
      {
        "status": "affected",
        "version": "version M2.1.6.05"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "IP Camera CF7501",
    "vendor": "Zavio",
    "versions": [
      {
        "status": "affected",
        "version": "version M2.1.6.05"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "IP Camera CB3211",
    "vendor": "Zavio",
    "versions": [
      {
        "status": "affected",
        "version": "version M2.1.6.05"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "IP Camera CB3212",
    "vendor": "Zavio",
    "versions": [
      {
        "status": "affected",
        "version": "version M2.1.6.05"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "IP Camera CB5220",
    "vendor": "Zavio",
    "versions": [
      {
        "status": "affected",
        "version": "version M2.1.6.05"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "IP Camera CB6231",
    "vendor": "Zavio",
    "versions": [
      {
        "status": "affected",
        "version": "version M2.1.6.05"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "IP Camera B8520",
    "vendor": "Zavio",
    "versions": [
      {
        "status": "affected",
        "version": "version M2.1.6.05"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "IP Camera B8220",
    "vendor": "Zavio",
    "versions": [
      {
        "status": "affected",
        "version": "version M2.1.6.05"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "IP Camera CD321",
    "vendor": "Zavio",
    "versions": [
      {
        "status": "affected",
        "version": "version M2.1.6.05"
      }
    ]
  }
]

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.1%

Related for CVE-2023-39435