Circutor COMPACT DC-S BASIC
Published May 24, 2022
8.1
HIGHCVSS 3.1
EPSS 0.80%
Description
A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The device runs a CGI binary (index.cgi) to offer a management web application. Once authenticated with valid credentials in this web portal, a potential attacker could submit any "Address" value and it would be copied to a second variable with a "strcpy" vulnerable function without checking its length. Because of this, it is possible to send a long address value to overflow the process stack, controlling the function return address.
Affected products
-
- Version CIR_CDC_v1.2.17StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Circutor | Compact DC-S Basic | n/a |
|
- 1.2.17
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Circutor has not responded to requests to work with CISA to mitigate this vulnerability. Users of these affected products are invited to contact Circutor customer support for additional information.
References (1)
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-137-01 x_refsource_MISCThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-137-01 | x_refsource_MISCThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.