CB6231, B8520, B8220, and CD321 IP Cameras
with firmware version M2.1.6.05 are
vulnerable to stack-based overflows. During the process of updating
certain settings sent from incoming network requests, the product does
not sufficiently check or validate allocated buffer size. This may lead
to remote code execution.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Zavio
Subscribe
|
B8220
Subscribe
B8220 Firmware
Subscribe
B8520
Subscribe
B8520 Firmware
Subscribe
Cb3211
Subscribe
Cb3211 Firmware
Subscribe
Cb3212
Subscribe
Cb3212 Firmware
Subscribe
Cb5220
Subscribe
Cb5220 Firmware
Subscribe
Cb6231
Subscribe
Cb6231 Firmware
Subscribe
Cd321
Subscribe
Cd321 Firmware
Subscribe
Cf7201
Subscribe
Cf7201 Firmware
Subscribe
Cf7300
Subscribe
Cf7300 Firmware
Subscribe
Cf7500
Subscribe
Cf7500 Firmware
Subscribe
Cf7501
Subscribe
Cf7501 Firmware
Subscribe
|
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-43159 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to stack-based overflows. During the process of updating certain settings sent from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution. |
Solution
No solution given by the vendor.
Workaround
The affected products are end-of-life and have been identified to contain many insecurities. The vendor, Zavio, is no longer actively in business and therefore development for firmware fixes, mitigations, and updates are not available and will not become available. CISA recommends users discontinue use of the product.
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:26:22.506Z
Reserved: 2023-10-10T22:30:47.603Z
Link: CVE-2023-39435
Updated: 2024-08-02T18:10:20.723Z
Status : Modified
Published: 2023-11-08T23:15:08.310
Modified: 2024-11-21T08:15:25.190
Link: CVE-2023-39435
No data.
OpenCVE Enrichment
No data.
EUVD