CVE-2024-23923: (Pwn2Own) Alpine Halo9 prh_l2_sar_data_ind Use-After-Free Remote Code Execution Vulnerability
Alpine Halo9 prhl2sardataind Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the prhl2sardataind function. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of root.
Was ZDI-CAN-22945
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23923?
CVE-2024-23923 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-23923?
To mitigate CVE-2024-23923, it is recommended to upgrade Alpine Halo9 devices to the latest firmware version that addresses this vulnerability.
Who is affected by CVE-2024-23923?
CVE-2024-23923 affects installations of Alpine Halo9 devices, particularly those running the identified firmware version 6.0.000.
Can CVE-2024-23923 be exploited without authentication?
Yes, CVE-2024-23923 can be exploited by network-adjacent attackers without requiring authentication.
What type of vulnerability is CVE-2024-23923?
CVE-2024-23923 is a use-after-free vulnerability that allows for remote code execution.