« Volver al listado

CVE-2023-49700

Estado: ModificadaAlta (7.5)—

Security best practices violations, a string operation in Streamingmedia will write past the end of fixed-size destination buffer if the source buffer is too large.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-49700",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "68630edc-a58c-4cbd-9b01-0e130455c8ae",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 1.4
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "68630edc-a58c-4cbd-9b01-0e130455c8ae",
      "affectedData": [
        {
          "vendor": "ASR",
          "product": "Falcon",
          "versions": [
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "CP01.057.063",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-30T07:15:09.967",
  "references": [
    {
      "url": "https://www.asrmicro.com/en/goods/psirt?cid=31",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "68630edc-a58c-4cbd-9b01-0e130455c8ae"
    },
    {
      "url": "https://www.asrmicro.com/en/goods/psirt?cid=31",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "68630edc-a58c-4cbd-9b01-0e130455c8ae",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Security best practices violations, a string operation in Streamingmedia will write past the end of fixed-size destination buffer if the source buffer is too large.  "
    },
    {
      "lang": "es",
      "value": "Violaciones de las mejores prácticas de seguridad: una operación de cadena en Streamingmedia escribirá más allá del final del búfer de destino de tamaño fijo si el búfer de origen es demasiado grande."
    }
  ],
  "lastModified": "2026-06-17T06:36:19.927",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:asrmicro:asr1803_firmware:cp01.057.063:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE40A33D-2C56-4084-B9C6-8D80757BD3BC"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:asrmicro:asr1803:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5DCCB900-92E3-4060-B687-052F378AC304"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:asrmicro:asr1806_firmware:cp01.057.063:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6EEE19F-252B-4D0E-A357-00581343A9DB"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:asrmicro:asr1806:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A9465207-5C99-406B-824E-B735FEDAA22D"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "68630edc-a58c-4cbd-9b01-0e130455c8ae"
}