Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03 Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2023-11-08T23:02:55.581Z

Updated: 2023-11-08T23:02:55.581Z

Reserved: 2023-07-26T18:38:50.354Z


Link: CVE-2023-3959

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-11-08T23:15:08.523

Modified: 2024-05-17T02:27:58.467


Link: CVE-2023-3959

JSON object: View

cve-icon Redhat Information

No data.