CVE-2024-44415

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 120

Summary

CVE-2024-44415: A vulnerability has been identified in DI_8200-16.07.26A1, which involves a buffer overflow in the dbsrv_asp function. This issue arises due to the strcpy function being executed without proper size checking, leading to an excessive amount of data being written to the buffer, potentially causing it to overflow and resulting in unintended system behavior or crashes. This flaw may be exploited remotely or locally to execute arbitrary code or disrupt services, posing a significant risk to affected systems. Users are advised to apply the necessary patches or updates to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share