Stack-based buffer overflow in message parser functionality
Published May 15, 2024
8.8
HIGHCVSS 3.1
EPSS 1.02%
Description
A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A specially crafted message can lead to stack-based buffer overflow. An attacker can make authenticated requests to trigger this vulnerability.
Affected products
-
- Version 0StatusaffectedConstraints<=3.0.2.4679
- Version
-
- Version 0StatusaffectedConstraints<=4.36.11.5859
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Roku | Indoor Camera SE | unaffected |
| ||||||
| Wyze | Cam v3 | unaffected |
|
Configuration 1
- 4.36.11.5859
Configuration 2
- 3.0.2.4679
Running on/with
- n/a
Configuration 3
- n/a
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Roku | Indoor Camera SE | n/a |
| |||
| Wyze | Cam V3 | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
- https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/ ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/ | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.