Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

EPSS

Процентиль: 42%
0.00201
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a KeyTurner device. This affects Nuki Smart Lock 3.0 before 3.3.5 and 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

EPSS

Процентиль: 42%
0.00201
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-120