Описание
In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.0.0 (включая) до 3.1.0 (включая)
cpe:2.3:a:eclipse:4diac_forte:*:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00601
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-416
Связанные уязвимости
CVSS3: 9.8
github
3 месяца назад
In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).
EPSS
Процентиль: 47%
0.00601
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-416