First published: Thu Jun 20 2019(Updated: )
A heap-based buffer overflow in cosa_dhcpv4_dml.c in the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve remote code execution by crafting a long buffer in the "Comment" field of an IP reservation form in the admin panel. This is related to the CcspCommonLibrary module.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rdkcentral Rdkb Ccsppandm | =rdkb-20181217-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-6963.
The severity of CVE-2019-6963 is high (8.8/10).
CVE-2019-6963 allows remote code execution by crafting a long buffer in the "Comment" field of an IP reservation form in the admin panel.
The RDK RDKB-20181217-1 CcspPandM module is affected by CVE-2019-6963.
There is no information available about a fix for CVE-2019-6963 at this time.