CVE-2023-3959

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zavio:cf7500_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cf7500:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:zavio:cf7300_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cf7300:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:zavio:cf7201_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cf7201:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:zavio:cf7501_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cf7501:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:zavio:cb3211_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cb3211:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:zavio:cb3212_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cb3212:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:zavio:cb5220_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cb5220:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:zavio:cb6231_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cb6231:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:zavio:b8520_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:b8520:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:zavio:b8220_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:b8220:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:zavio:cd321_firmware:m2.1.6.05:*:*:*:*:*:*:*
cpe:2.3:h:zavio:cd321:-:*:*:*:*:*:*:*

History

21 Mar 2024, 02:48

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-08 23:15

Updated : 2024-08-02 07:16


NVD link : CVE-2023-3959

Mitre link : CVE-2023-3959

CVE.ORG link : CVE-2023-3959


JSON object : View

Products Affected

zavio

  • cb3211_firmware
  • cb5220
  • cf7501
  • cd321_firmware
  • cf7300
  • b8520_firmware
  • cd321
  • cf7300_firmware
  • cf7501_firmware
  • cb3212_firmware
  • cb6231_firmware
  • cb3211
  • b8220_firmware
  • cf7201_firmware
  • cb3212
  • b8520
  • cb5220_firmware
  • b8220
  • cf7500_firmware
  • cf7201
  • cb6231
  • cf7500
CWE
CWE-787

Out-of-bounds Write

CWE-121

Stack-based Buffer Overflow