Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pjhf-85h3-g8m3

Опубликовано: 02 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 9.8

Описание

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundary checking. This can lead to memory corruption, resulting in possible remote code execution.

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundary checking. This can lead to memory corruption, resulting in possible remote code execution.

EPSS

Процентиль: 47%
0.0024
Низкий

8.5 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 9.8
nvd
2 месяца назад

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundary checking. This can lead to memory corruption, resulting in possible remote code execution.

EPSS

Процентиль: 47%
0.0024
Низкий

8.5 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-121