CVE-2019-6964: High severity rdkcentral rdkb ccsppandm vulnerability
A heap-based buffer over-read in ServiceSetParamStringValue in cosaxciscocomddnsdml.c of the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve information disclosure and code execution by crafting an AJAX call responsible for DDNS configuration with an exactly 64-byte username, password, or domain, for which the buffer size is insufficient for the final '\0' character. This is related to the CcspCommonLibrary and WebUI modules.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-6964.
What is the severity of CVE-2019-6964?
The severity of CVE-2019-6964 is high with a severity value of 8.8.
How can attackers exploit CVE-2019-6964?
Attackers with login credentials can exploit CVE-2019-6964 by crafting an AJAX call responsible for DDNS configuration.
What can attackers achieve by exploiting CVE-2019-6964?
Attackers can achieve information disclosure and code execution by exploiting CVE-2019-6964.
Is there a fix available for CVE-2019-6964?
Please refer to the provided reference link for information on how to mitigate CVE-2019-6964.