Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-22547

Опубликовано: 04 мая 2021
Источник: nvd
CVSS3: 6.3
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in memory objects larger than the buffer and wrap around to have a smaller buffer than required, allowing the attacker access to the other parts of the heap. We recommend upgrading the Google Cloud IoT Device SDK for Embedded C used to 1.0.3 or greater.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:google:cloud_iot_device_sdk_for_embedded_c:*:*:*:*:*:*:*:*
Версия до 1.0.3 (исключая)

EPSS

Процентиль: 7%
0.00026
Низкий

6.3 Medium

CVSS3

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-120
CWE-120

Связанные уязвимости

github
больше 3 лет назад

In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in memory objects larger than the buffer and wrap around to have a smaller buffer than required, allowing the attacker access to the other parts of the heap. We recommend upgrading the Google Cloud IoT Device SDK for Embedded C used to 1.0.3 or greater.

EPSS

Процентиль: 7%
0.00026
Низкий

6.3 Medium

CVSS3

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-120
CWE-120