Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-45318


A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.


Published

2024-02-20T15:15:08.727

Last Modified

2025-02-12T18:50:45.040

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 10.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-122
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application silabs gecko_software_development_kit 4.3.2.0 Yes
Application weston-embedded uc-http - Yes

References