Impact
The vulnerability arises from buffer overflow in CipAttribute::SetAttrData and GetAttrData functions within ciptypes.h. The overflow can corrupt memory, allowing an attacker to manipulate program state. If executed, this flaw could enable arbitrary code execution or system compromise. The flaw is an instance of CWE‑119, which describes buffer over-read and write risks.
Affected Systems
The affected product is liftoff‑sr CIPster, specifically the release identified by commit 1802525be27d33e19a9a83c163e331a1d13b1892. No other version range is disclosed; the patch commit e745d9d4a8ca3a13689066983a1269fe1e567674 is to be applied to this codebase to fix the issue.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, so the statistical likelihood of exploitation cannot be quantified, but the vulnerability is listed as publicly available and exploitable. It is not yet in KEV. A remote attacker can exploit the flaw over the network, so the risk is significant for exposed services.
OpenCVE Enrichment