CVE-2023-49236: Buffer Overflow
Published Jan 9, 2024
·Updated
A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command execution. This occurs because of lack of length validation during an sscanf of a user-entered scale field in the RTSP playback function of davinci.
Affected Software
2 affected components
All of the following
Trendnet Tv-ip1314pi Firmware=5.5.3-200714
Trendnet TV-IP1314PI
Event History
Jan 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49236?
CVE-2023-49236 has a critical severity rating due to its potential for arbitrary command execution.
2
How do I fix CVE-2023-49236?
To fix CVE-2023-49236, update the firmware of the TRENDnet TV-IP1314PI to the latest version that addresses this vulnerability.
3
What devices are affected by CVE-2023-49236?
CVE-2023-49236 affects TRENDnet TV-IP1314PI devices running firmware version 5.5.3 200714.
4
What type of vulnerability is CVE-2023-49236?
CVE-2023-49236 is a stack-based buffer overflow vulnerability.
5
What impact does CVE-2023-49236 have on affected devices?
CVE-2023-49236 allows attackers to execute arbitrary commands on affected devices.