CVE-2023-25181: Buffer Overflow
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this heap-based buffer overflow vulnerability?
The vulnerability ID is CVE-2023-25181.
What is the severity level of CVE-2023-25181?
CVE-2023-25181 has a severity level of critical (9).
Which software is affected by CVE-2023-25181?
The Silabs Gecko Software Development Kit version 4.3.1, Weston-embedded Cesium Net version 3.07.01, and Weston-embedded Uc-http version 3.01.01 are affected by CVE-2023-25181.
What is the potential impact of CVE-2023-25181?
CVE-2023-25181 can allow an attacker to execute arbitrary code by sending a specially crafted set of network packets.
Are there any references for CVE-2023-25181?
Yes, you can find more information about CVE-2023-25181 at the following links: - [Talos Intelligence](https://talosintelligence.com/vulnerability_reports/TALOS-2023-1726) - [Talos Intelligence](https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1726)