CVE-2023-28582

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 4, 2024
Updated: Jan 10, 2025
CWE ID 787
CWE ID 120

Summary

CVE-2023-28582 is a memory corruption vulnerability affecting Data Modem software during the DTLS handshake process. Specifically, it occurs when the software verifies the hello-verify message. An attacker who successfully exploits this vulnerability could gain unauthorized control over an affected system or cause it to crash. This issue poses a significant risk to organizations using Data Modem software and highlights the importance of timely software updates and patches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share