CVE-2024-46215

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 120

Summary

CVE-2024-46215 is a newly discovered buffer overflow vulnerability affecting the KM08-708H-v1.1 version of the goahead software. The issue lies within the sub_445BDC() function located in the /usr/sbin/goahead program. Due to an lack of input validation, the strcpy function is executed without proper length checks, creating an opportunity for attackers to write arbitrary data beyond the intended buffer, potentially leading to code execution or system instability. This vulnerability poses a significant risk to systems running the affected software and requires immediate attention from administrators for patching or mitigation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share