Описание
In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not have sufficient bounds checks. This may result in a stack-based buffer overflow.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 200.001.00.p027 (исключая)
Одновременно
cpe:2.3:o:sungrowpower:winet-s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sungrowpower:winet-s:-:*:*:*:*:*:*:*
EPSS
Процентиль: 35%
0.00148
Низкий
8.1 High
CVSS3
Дефекты
CWE-120
Связанные уязвимости
CVSS3: 8.1
github
около 1 года назад
In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not have sufficient bounds checks. This may result in a stack-based buffer overflow.
EPSS
Процентиль: 35%
0.00148
Низкий
8.1 High
CVSS3
Дефекты
CWE-120