CVE-2024-10964: emqx neuron plugin_handle.c handle_add_plugin buffer overflow
Published Nov 7, 2024
·Updated
A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handleaddplugin in the library cmd.library of the file plugins/restful/pluginhandle.c. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.
Affected Software
1 affected component
emqx neuron<=2.10.0
Remediation
Patch Available
Event History
Nov 7, 2024
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-10964?
CVE-2024-10964 is classified as a critical vulnerability.
2
How do I fix CVE-2024-10964?
To fix CVE-2024-10964, update emqx neuron to version 2.10.1 or later.
3
What kind of vulnerability is CVE-2024-10964?
CVE-2024-10964 is a buffer overflow vulnerability.
4
Which versions of emqx neuron are affected by CVE-2024-10964?
Emqx neuron versions up to and including 2.10.0 are affected by CVE-2024-10964.
5
Can CVE-2024-10964 be exploited remotely?
Yes, CVE-2024-10964 can be exploited remotely.