First published: Thu Jan 26 2023(Updated: )
A stack-based buffer overflow vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siretta Quartz-gold Firmware | =g5.0.1.5-210720-141020 | |
Siretta QUARTZ-GOLD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36279 is considered critical due to the potential for remote code execution through a stack-based buffer overflow.
To mitigate CVE-2022-36279, update the Siretta Quartz-GOLD firmware to a patched version that resolves this vulnerability.
CVE-2022-36279 affects Siretta Quartz-GOLD firmware version g5.0.1.5-210720-141020.
Yes, CVE-2022-36279 can be exploited remotely by sending specially-crafted HTTP requests.
Exploiting CVE-2022-36279 may allow an attacker to execute arbitrary code on the affected system.