{"id": "CVE-2023-45225", "cveTags": [{"tags": ["unsupported-when-assigned"], "sourceIdentifier": "
[email protected]"}], "metrics": {"cvssMetricV31": [{"type": "Secondary", "source": "
[email protected]", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}, {"type": "Primary", "source": "
[email protected]", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2023-11-08T23:15:11.790", "references": [{"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03", "tags": ["Third Party Advisory", "US Government Resource"], "source": "
[email protected]"}, {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03", "tags": ["Third Party Advisory", "US Government Resource"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Secondary", "source": "
[email protected]", "description": [{"lang": "en", "value": "CWE-121"}]}, {"type": "Primary", "source": "
[email protected]", "description": [{"lang": "en", "value": "CWE-787"}]}], "descriptions": [{"lang": "en", "value": "Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,\n CB6231, B8520, B8220, and CD321 \n\nIP Cameras\u00a0 with firmware version M2.1.6.05 are \nvulnerable to multiple instances of stack-based overflows. While parsing\n certain XML elements from incoming network requests, the product does \nnot sufficiently check or validate allocated buffer size. This may lead \nto remote code execution.\n\n"}, {"lang": "es", "value": "IP Cameras Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220 y CD321 con versi\u00f3n de firmware M2.1.6.05 son vulnerables a m\u00faltiples instancias de desbordamientos basados en pila. Al analizar ciertos elementos XML de solicitudes de red entrantes, el producto no verifica ni valida suficientemente el tama\u00f1o del b\u00fafer asignado. Esto puede provocar la ejecuci\u00f3n remota de c\u00f3digo."}], "lastModified": "2024-11-21T08:26:34.990", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:zavio:cf7500_firmware:m2.1.6.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D543FC87-52FF-4BC4-BE57-949BB23D88AD"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:zavio:cf7500:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "30F595D2-3CB4-4444-A01F-CE38CBE2D0DC"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:zavio:cf7300_firmware:m2.1.6.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FA43E48-E3D0-4913-9040-BF11D9E61385"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:zavio:cf7300:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B008EE1F-5B08-417A-8206-20F1362DB911"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:zavio:cf7201_firmware:m2.1.6.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7A6E3CDA-3C8B-4894-A42A-CFC5AA077047"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:zavio:cf7201:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B5240BE7-31E4-4A40-A480-E744E3CAEA3A"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:zavio:cf7501_firmware:m2.1.6.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5CF6549F-9E86-4B45-8B60-BB62BEB72B19"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:zavio:cf7501:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9285F916-50BE-4E41-8EF3-97D882B54CD6"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:zavio:cb3211_firmware:m2.1.6.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3F7DBB50-D334-493F-B661-04C798383D29"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:zavio:cb3211:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1C32A113-76F5-4EBD-BD15-EFBB17F0942C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:zavio:cb3212_firmware:m2.1.6.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "883549EB-5A5B-437E-8B10-D7C691142B92"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:zavio:cb3212:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FC86EF14-298F-414E-8558-1D025CDF6057"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:zavio:cb5220_firmware:m2.1.6.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C43C9ED3-167E-4424-841E-50A56FF398F0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:zavio:cb5220:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AFEC44B0-C2C7-4306-91CA-AA841B23498D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:zavio:cb6231_firmware:m2.1.6.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E8483A6-426F-4595-8B7F-1FC04E9B31FF"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:zavio:cb6231:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "766018BD-DD32-420A-9511-D97D9DE46BBA"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:zavio:b8520_firmware:m2.1.6.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "779DE260-60AA-465E-957D-B7502E806863"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:zavio:b8520:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F60E1FE1-F2E8-4BF7-A33D-4ED4D72BF360"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:zavio:b8220_firmware:m2.1.6.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "99AC7EEC-C4A5-4F79-9608-D02E29356217"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:zavio:b8220:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8623A941-0514-49BD-967D-E347F6F99329"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:zavio:cd321_firmware:m2.1.6.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35DCACBC-6483-4113-BC77-041BE4D692F9"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:zavio:cd321:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4E906053-BE44-45B4-AD08-D7DFCFD5EDF2"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "
[email protected]"}