CVE-2024-21525

HIGH

NPM Node-twain - Buffer Overflow

Title source: rule
STIX 2.1

Description

All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the length of the source data not being checked. Creating a new twain.TwainSDK with a productName or productFamily, manufacturer, version.info property of length >= 34 chars leads to a buffer overflow vulnerability.

Scores

CVSS v3 8.3
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-703
Status published
Products (2)
n/a/node-twain
npm/node-twain 0npm
Published Jul 10, 2024
Tracked Since Feb 18, 2026