CVE-2023-39435

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
08/11/2023
Last modified:
02/08/2024

Description

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,<br /> CB6231, B8520, B8220, and CD321 IP Cameras <br /> <br /> with firmware version M2.1.6.05 are <br /> vulnerable to stack-based overflows. During the process of updating <br /> certain settings sent from incoming network requests, the product does <br /> not sufficiently check or validate allocated buffer size. This may lead <br /> to remote code execution.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:zavio:cf7500:-:*:*:*:*:*:*:*
cpe:2.3:o:zavio:cf7500_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cf7300:-:*:*:*:*:*:*:*
cpe:2.3:o:zavio:cf7300_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cf7201:-:*:*:*:*:*:*:*
cpe:2.3:o:zavio:cf7201_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cf7501:-:*:*:*:*:*:*:*
cpe:2.3:o:zavio:cf7501_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cb3211:-:*:*:*:*:*:*:*
cpe:2.3:o:zavio:cb3211_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cb3212:-:*:*:*:*:*:*:*
cpe:2.3:o:zavio:cb3212_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cb5220:-:*:*:*:*:*:*:*
cpe:2.3:o:zavio:cb5220_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cb6231:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools