Lucene search

K
cvelistIcscertCVELIST:CVE-2023-23582
HistoryJan 30, 2023 - 10:08 p.m.

CVE-2023-23582

2023-01-3022:08:49
CWE-122
icscert
www.cve.org
snap one
wattbox wb-300-ip-3
heap-based buffer overflow
remote code execution

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

9.9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.8%

Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior are vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code or crash the device remotely.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Wattbox WB-300-IP-3",
    "vendor": "Snap One",
    "versions": [
      {
        "lessThanOrEqual": "WB10.9a17",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

9.9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.8%

Related for CVELIST:CVE-2023-23582