CVE-2024-13503
Severity CVSS v4.0:
CRITICAL
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
17/01/2025
Last modified:
17/01/2025
Description
Buffer Copy without Checking Size of Input (&#39;Classic Buffer Overflow&#39;) vulnerability in Newtec NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM (Updating signaling process in the swdownload binary modules) allows Local Execution of Code, Remote Code Inclusion.<br />
This issue affects NTC2218, NTC2250, NTC2299: from 1.0.1.1 through 2.2.6.19. The issue is both present on the PowerPC versions of the modem and the ARM versions.<br />
<br />
A stack buffer buffer overflow in the swdownload binary allows attackers to execute arbitrary code. The parse_INFO function uses an unrestricted `sscanf` to read a string of an incoming network packet into a statically sized buffer.
Impact
Base Score 4.0
9.50
Severity 4.0
CRITICAL