Логотип exploitDog
bind:CVE-2022-2347
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-2347

Количество 5

Количество 5

ubuntu логотип

CVE-2022-2347

больше 3 лет назад

There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2022-2347

больше 3 лет назад

There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2022-2347

больше 3 лет назад

There exists an unchecked length field in UBoot. The U-Boot DFU implem ...

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-57ww-qgjv-3g3c

больше 3 лет назад

There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2025-13599

почти 4 года назад

Уязвимость компонента drivers/usb/gadget/f_dfu.c загрузчика U-Boot, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-2347

There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.

CVSS3: 7.7
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2347

There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.

CVSS3: 7.7
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2347

There exists an unchecked length field in UBoot. The U-Boot DFU implem ...

CVSS3: 7.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-57ww-qgjv-3g3c

There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2025-13599

Уязвимость компонента drivers/usb/gadget/f_dfu.c загрузчика U-Boot, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 7.7
0%
Низкий
почти 4 года назад

Уязвимостей на страницу