Description


Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior are vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code or crash the device remotely.

References


https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-03

Third Party AdvisoryUS Government Resource

Weaknesses



CWE-787


CWE-122

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-01-30T23:15:11.537

1 year ago

Last modified

2023-11-07T04:07:46.990

8 months ago