Lucene search

K
vulnrichmentNIVULNRICHMENT:CVE-2023-4601
HistoryOct 18, 2023 - 7:15 p.m.

CVE-2023-4601 Stack-based Buffer Overflow in NI System Configuration Software

2023-10-1819:15:33
CWE-121
NI
github.com
1
buffer overflow
system configuration
information disclosure
arbitrary code execution
ni system configuration 2023 q3

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

55.6%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

total

A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosure and/or arbitrary code execution. Successful exploitation requires that an attacker can provide a specially crafted response. This affects NI System Configuration 2023 Q3 and all previous versions.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:ni:system_configuration:*:*:*:*:*:*:*:*"
    ],
    "vendor": "ni",
    "product": "system_configuration",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "23.5"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

55.6%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

total

Related for VULNRICHMENT:CVE-2023-4601