Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r7vh-g6cm-2j84

Опубликовано: 23 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Toybox.Ant.BurstPayload.add API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted Toybox.Ant.BurstPayload object, call its add method, override arbitrary memory and hijack the execution of the device's firmware.

The Toybox.Ant.BurstPayload.add API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted Toybox.Ant.BurstPayload object, call its add method, override arbitrary memory and hijack the execution of the device's firmware.

EPSS

Процентиль: 66%
0.00509
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted `Toybox.Ant.BurstPayload` object, call its `add` method, override arbitrary memory and hijack the execution of the device's firmware.

EPSS

Процентиль: 66%
0.00509
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787