A CWE-120: Buffer Copy without Checking Size of Input...
Critical severity
Unreviewed
Published
Jan 31, 2023
to the GitHub Advisory Database
•
Updated Feb 15, 2023
Description
Published by the National Vulnerability Database
Jan 30, 2023
Published to the GitHub Advisory Database
Jan 31, 2023
Last updated
Feb 15, 2023
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm cache data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
References