CVE-2023-24585: Buffer Overflow
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-24585.
What is the severity rating of CVE-2023-24585?
The severity rating of CVE-2023-24585 is critical with a value of 9.8.
What software is affected by this vulnerability?
The Silabs Gecko Software Development Kit version 4.3.1, Weston-embedded Cesium Net version 3.07.01, and Weston-embedded Uc-http version 3.01.01 are affected by this vulnerability.
What is the Common Weakness Enumeration (CWE) ID associated with this vulnerability?
The Common Weakness Enumeration (CWE) IDs associated with this vulnerability are CWE-119 and CWE-787.
How can this vulnerability be exploited?
This vulnerability can be exploited by sending a specially crafted network packet to the HTTP Server functionality of Weston Embedded uC-HTTP, leading to memory corruption.