Memory Corruption Vulnerability in Weston Embedded uC-HTTP Server
CVE-2023-31247
9CRITICAL
What is CVE-2023-31247?
A memory corruption vulnerability has been identified in the HTTP Server Host header parsing functionality of the Weston Embedded uC-HTTP version 3.01.01. Exploitation of this vulnerability allows attackers to craft a malicious network packet, leading to possible code execution on the affected system. It is essential for organizations using this product to assess their exposure and implement necessary security measures to mitigate potential attacks.
Affected Version(s)
Cesium NET 3.07.01
Gecko Platform 4.3.1.0
uC-HTTP v3.01.01
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Kelly Leuschner of Cisco Talos.
