CVE-2023-39435
Summary
| CVE | CVE-2023-39435 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-08 23:15:00 UTC |
| Updated | 2023-11-15 20:47:00 UTC |
| Description | ** UNSUPPPORTED WHEN ASSIGNED ** Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to stack-based overflows. During the process of updating certain settings sent from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Zavio | B8220 | - | All | All | All |
| Operating System | Zavio | B8220 Firmware | m2.1.6.05 | All | All | All |
| Hardware | Zavio | B8520 | - | All | All | All |
| Operating System | Zavio | B8520 Firmware | m2.1.6.05 | All | All | All |
| Hardware | Zavio | Cb3211 | - | All | All | All |
| Operating System | Zavio | Cb3211 Firmware | m2.1.6.05 | All | All | All |
| Hardware | Zavio | Cb3212 | - | All | All | All |
| Operating System | Zavio | Cb3212 Firmware | m2.1.6.05 | All | All | All |
| Hardware | Zavio | Cb5220 | - | All | All | All |
| Operating System | Zavio | Cb5220 Firmware | m2.1.6.05 | All | All | All |
| Hardware | Zavio | Cb6231 | - | All | All | All |
| Operating System | Zavio | Cb6231 Firmware | m2.1.6.05 | All | All | All |
| Hardware | Zavio | Cd321 | - | All | All | All |
| Operating System | Zavio | Cd321 Firmware | m2.1.6.05 | All | All | All |
| Hardware | Zavio | Cf7201 | - | All | All | All |
| Operating System | Zavio | Cf7201 Firmware | m2.1.6.05 | All | All | All |
| Hardware | Zavio | Cf7300 | - | All | All | All |
| Operating System | Zavio | Cf7300 Firmware | m2.1.6.05 | All | All | All |
| Hardware | Zavio | Cf7500 | - | All | All | All |
| Operating System | Zavio | Cf7500 Firmware | m2.1.6.05 | All | All | All |
| Hardware | Zavio | Cf7501 | - | All | All | All |
| Operating System | Zavio | Cf7501 Firmware | m2.1.6.05 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zavio IP Camera | CISA | www.cisa.gov | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.