CVE-2022-26952

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
06/04/2022
Last modified:
12/04/2022

Description

Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unauthenticated user is redirected to the authentication page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:digi:passport_firmware:*:*:*:*:*:*:*:* 1.5.1.1 (including)
cpe:2.3:h:digi:passport:-:*:*:*:*:*:*:*