nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-50240 CVE-2023-50240
HIGH
Record summary
CVE-2023-50240 has a selected CVSS score of 7.2 (high).
Description
Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `AdvDefaultPreference` request's parameter.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 24, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
WBR-6013Browse LevelOne / WBR-6013Default status: unknown | CVE List | RER4_A_v3411b_2T2R_LEV_09_170623 | affected |
| rer4_a_v3411b_2t2r_lev_09_170623 | affected | ||
rtl819x Jungle SDKBrowse Realtek / rtl819x Jungle SDK | CVE List | v3.4.11 | affected |
rtl819x_software_development_kitBrowse realtek / rtl819x_software_development_kitDefault status: unknown | CVE List | 3.4.11 | affected |
References
3talosintelligence.com
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1893 talosintelligence.com
https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1893