Buffer Overflow Vulnerability in Draytek Vigor 3910 Product
CVE-2024-46564
7.5HIGH
Summary
The Draytek Vigor 3910 is exposed to a buffer overflow vulnerability in the sProfileName parameter, specifically found in the fextobj.cgi component. By crafting specific inputs, attackers can exploit this vulnerability, which can lead to a Denial of Service situation. This means that legitimate users may be unable to access the necessary services, therefore affecting the overall functionality of the Draytek Vigor 3910 device. Timely updates and security patches from the vendor are essential to mitigate the risk associated with this vulnerability.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published