CVE-2023-4249
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321
IP Cameras
with firmware version M2.1.6.05 has a
command injection vulnerability in their implementation of their
binaries and handling of network requests.
Affected (11)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version m2.1.6.05 |
| Running on/with | Platform Versions |
|---|---|
Zavio Cf7500 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version m2.1.6.05 |
| Running on/with | Platform Versions |
|---|---|
Zavio Cf7300 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version m2.1.6.05 |
| Running on/with | Platform Versions |
|---|---|
Zavio Cf7201 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version m2.1.6.05 |
| Running on/with | Platform Versions |
|---|---|
Zavio Cf7501 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version m2.1.6.05 |
| Running on/with | Platform Versions |
|---|---|
Zavio Cb3211 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version m2.1.6.05 |
| Running on/with | Platform Versions |
|---|---|
Zavio Cb3212 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version m2.1.6.05 |
| Running on/with | Platform Versions |
|---|---|
Zavio Cb5220 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version m2.1.6.05 |
| Running on/with | Platform Versions |
|---|---|
Zavio Cb6231 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version m2.1.6.05 |
| Running on/with | Platform Versions |
|---|---|
Zavio B8520 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version m2.1.6.05 |
| Running on/with | Platform Versions |
|---|---|
Zavio B8220 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version m2.1.6.05 |
| Running on/with | Platform Versions |
|---|---|
Zavio Cd321 | All versions |
Related CWEs
CWE-121
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.