CVE-2022-2025
Summary
| CVE | CVE-2022-2025 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-23 16:15:00 UTC |
| Updated | 2022-09-26 22:37:00 UTC |
| Description | an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Grandstream | Gds3710 | - | All | All | All |
| Operating System | Grandstream | Gds3710 Firmware | 1.0.11.13 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Buffer overflow vulnerabilities in Grandstream GSD3710 | INCIBE-CERT | CONFIRM | www.incibe-cert.es | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: José Luis Verdeguer Navarro
There are currently no legacy QID mappings associated with this CVE.