CVE-2023-45591

A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated attacker to trigger a memory corruption in the context of the binary. This may result in a Denial-of-Service (DoS) condition, possibly in the execution of arbitrary code with the same privileges of the process (root), or have other unspecified impacts on the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ailux:imx6:*:*:*:*:*:*:*:*

History

10 Apr 2025, 20:35

Type Values Removed Values Added
CWE CWE-787
References () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-45591 - () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-45591 - Third Party Advisory
First Time Ailux
Ailux imx6
CPE cpe:2.3:a:ailux:imx6:*:*:*:*:*:*:*:*

21 Nov 2024, 08:27

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad CWE-122 de “desbordamiento de búfer de almacenamiento dinámico” en la función “logger_generic” del binario “Ax_rtu” permite que un atacante remoto autenticado desencadene una corrupción de memoria en el contexto del binario. Esto puede resultar en una condición de Denegación de Servicio (DoS), posiblemente en la ejecución de código arbitrario con los mismos privilegios del proceso (raíz), o tener otros impactos no especificados en el dispositivo. Este problema afecta: Paquete AiLux imx6 inferior a la versión imx6_1.0.7-2.
References () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-45591 - () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-45591 -

05 Mar 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-05 12:15

Updated : 2025-04-10 20:35


NVD link : CVE-2023-45591

Mitre link : CVE-2023-45591

CVE.ORG link : CVE-2023-45591


JSON object : View

Products Affected

ailux

  • imx6
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write