Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2023-21406

Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-787 Escritura fuera de límites
Fecha de publicación:
25/07/2023
Última modificación:
08/11/2024

Descripción

*** Pendiente de traducción *** Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when<br /> communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which<br /> is handling the OSDP communication allowing to write outside of the allocated buffer. By<br /> appending invalid data to an OSDP message it was possible to write data beyond the heap<br /> allocated buffer. The data written outside the buffer could be used to execute arbitrary code. <br /> <br /> lease refer to the Axis security advisory for more information, mitigation and affected products and software versions.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:axis:a1001_firmware:*:*:*:*:*:*:*:* 1.65.4 (incluyendo)
cpe:2.3:h:axis:a1001:-:*:*:*:*:*:*:*


Referencias a soluciones, herramientas e información