2025-03-02 03:03:52 +00:00

86 lines
4.2 KiB
JSON

{
"id": "CVE-2024-13503",
"sourceIdentifier": "vulnerability@ncsc.ch",
"published": "2025-01-17T14:15:31.317",
"lastModified": "2025-01-17T14:15:31.317",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM (Updating signaling process in the swdownload binary modules) allows Local Execution of Code, Remote Code Inclusion.\nThis issue affects NTC2218, NTC2250, NTC2299: from 1.0.1.1 through 2.2.6.19. The issue is both present on the PowerPC versions of the modem and the ARM versions.\n\nA stack buffer buffer overflow in the swdownload binary allows attackers to execute arbitrary code. The parse_INFO function uses an unrestricted `sscanf` to read a string of an incoming network packet into a statically sized buffer."
},
{
"lang": "es",
"value": "Vulnerabilidad de copia de b\u00fafer sin comprobar el tama\u00f1o de la entrada ('desbordamiento de b\u00fafer cl\u00e1sico') en Newtec NTC2218, NTC2250, NTC2299 en Linux, PowerPC, ARM (el proceso de se\u00f1alizaci\u00f3n de actualizaci\u00f3n en los m\u00f3dulos binarios swdownload) permite la ejecuci\u00f3n local de c\u00f3digo y la inclusi\u00f3n remota de c\u00f3digo. Este problema afecta a NTC2218, NTC2250, NTC2299: desde la versi\u00f3n 1.0.1.1 hasta la versi\u00f3n 2.2.6.19. El problema est\u00e1 presente tanto en las versiones PowerPC del m\u00f3dem como en las versiones ARM. Un desbordamiento de b\u00fafer de pila en el binario swdownload permite a los atacantes ejecutar c\u00f3digo arbitrario. La funci\u00f3n parse_INFO utiliza un `sscanf` sin restricciones para leer una cadena de un paquete de red entrante en un b\u00fafer de tama\u00f1o est\u00e1tico."
}
],
"metrics": {
"cvssMetricV40": [
{
"source": "vulnerability@ncsc.ch",
"type": "Secondary",
"cvssData": {
"version": "4.0",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"baseScore": 9.5,
"baseSeverity": "CRITICAL",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"subAvailabilityImpact": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"confidentialityRequirement": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"availabilityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED"
}
}
]
},
"weaknesses": [
{
"source": "vulnerability@ncsc.ch",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
}
],
"references": [
{
"url": "https://doi.org/10.1145/3643833.3656139",
"source": "vulnerability@ncsc.ch"
},
{
"url": "https://www.youtube.com/watch?v=-pxmly8xeas",
"source": "vulnerability@ncsc.ch"
}
]
}