Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j9mv-375p-293q

Опубликовано: 14 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.3

Описание

Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker with device configuration access to write attacker-controlled data outside the bounds of the process-image buffer and corrupt adjacent kernel memory, resulting in kernel memory corruption and denial of service, by supplying crafted device configuration data and crafted input through the piControl character device.

Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker with device configuration access to write attacker-controlled data outside the bounds of the process-image buffer and corrupt adjacent kernel memory, resulting in kernel memory corruption and denial of service, by supplying crafted device configuration data and crafted input through the piControl character device.

EPSS

Процентиль: 1%
0.00099
Низкий

7.3 High

CVSS4

Дефекты

CWE-787

Связанные уязвимости

nvd
около 1 месяца назад

Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker with device configuration access to write attacker-controlled data outside the bounds of the process-image buffer and corrupt adjacent kernel memory, resulting in kernel memory corruption and denial of service, by supplying crafted device configuration data and crafted input through the piControl character device.

EPSS

Процентиль: 1%
0.00099
Низкий

7.3 High

CVSS4

Дефекты

CWE-787