Lucene search

K
cvelistBitdefenderCVELIST:CVE-2023-6322
HistoryMay 15, 2024 - 12:08 p.m.

CVE-2023-6322 Stack-based buffer overflow in message parser functionality

2024-05-1512:08:24
CWE-121
Bitdefender
www.cve.org
2
cve-2023-6322
buffer overflow
message parser
roku indoor camera se
wyze cam v3
authenticated requests

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

9.1%

A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A specially crafted message can lead to stack-based buffer overflow. An attacker can make authenticated requests to trigger this vulnerability.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Indoor Camera SE",
    "vendor": "Roku",
    "versions": [
      {
        "lessThanOrEqual": "3.0.2.4679",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Cam v3",
    "vendor": "Wyze",
    "versions": [
      {
        "lessThanOrEqual": "4.36.11.5859",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

9.1%

Related for CVELIST:CVE-2023-6322