Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jxg-9cjf-4f5f

Опубликовано: 14 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

EPSS

Процентиль: 80%
0.01451
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 6.3
nvd
больше 1 года назад

An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

EPSS

Процентиль: 80%
0.01451
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-121