CVE-2023-45225
Last modified
CVE-2023-45225 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While parsing certain XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. EPSS estimates a 1.26% chance of exploitation in the next 30 days.
Description
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While parsing certain XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zavio | Cf7500 Firmware | m2.1.6.05 |
| Zavio | Cf7300 Firmware | m2.1.6.05 |
| Zavio | Cf7201 Firmware | m2.1.6.05 |
| Zavio | Cf7501 Firmware | m2.1.6.05 |
| Zavio | Cb3211 Firmware | m2.1.6.05 |
| Zavio | Cb3212 Firmware | m2.1.6.05 |
| Zavio | Cb5220 Firmware | m2.1.6.05 |
| Zavio | Cb6231 Firmware | m2.1.6.05 |
| Zavio | B8520 Firmware | m2.1.6.05 |
| Zavio | B8220 Firmware | m2.1.6.05 |
| Zavio | Cd321 Firmware | m2.1.6.05 |
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03Third Party Advisory, US Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-45225?
How severe is CVE-2023-45225?
How do I fix CVE-2023-45225?
Are you affected by CVE-2023-45225?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
