The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those function codes, the user must supply parameters. There is no sanitation on the value of the offset, which allows the client to specify any offset and read out-of-bounds data.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2021-24903 | The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those function codes, the user must supply parameters. There is no sanitation on the value of the offset, which allows the client to specify any offset and read out-of-bounds data. | 
Fixes
    Solution
AUVESY recommends upgrading Versiondog to Version 8.1 or later (login required).
Workaround
No workaround given by the vendor.
References
        | Link | Providers | 
|---|---|
| https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01 | 
                     | 
            
History
                    Tue, 17 Sep 2024 01:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | AUVESY Versiondog | AUVESY Versiondog | 
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-17T01:41:23.696Z
Reserved: 2021-08-10T00:00:00
Link: CVE-2021-38451
No data.
Status : Modified
Published: 2021-10-22T12:15:08.130
Modified: 2024-11-21T06:17:07.850
Link: CVE-2021-38451
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD