CB6231, B8520, B8220, and CD321
IP Cameras
with firmware version M2.1.6.05 are
vulnerable to multiple instances of stack-based overflows. While
processing XML elements from incoming network requests, the product does
not sufficiently check or validate allocated buffer size. This may lead
to remote code execution.
Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2023-44584 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution. | 
Solution
No solution given by the vendor.
Workaround
The affected products are end-of-life and have been identified to contain many insecurities. The vendor, Zavio, is no longer actively in business and therefore development for firmware fixes, mitigations, and updates are not available and will not become available. CISA recommends users discontinue use of the product.
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:25:58.442Z
Reserved: 2023-07-26T18:38:50.354Z
Link: CVE-2023-3959
Updated: 2024-08-02T07:08:50.665Z
Status : Modified
Published: 2023-11-08T23:15:08.523
Modified: 2024-11-21T08:18:24.233
Link: CVE-2023-3959
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD