CVE-2023-45318

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:silabs:gecko_software_development_kit:4.3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:weston-embedded:uc-http:-:*:*:*:*:*:*:*

History

12 Feb 2025, 18:50

Type Values Removed Values Added
CWE CWE-787
References () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1843 - () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1843 - Exploit, Third Party Advisory
CPE cpe:2.3:a:silabs:gecko_software_development_kit:4.3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:weston-embedded:uc-http:-:*:*:*:*:*:*:*
First Time Weston-embedded uc-http
Weston-embedded
Silabs gecko Software Development Kit
Silabs

21 Nov 2024, 08:26

Type Values Removed Values Added
References () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1843 - () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1843 -
Summary
  • (es) Existe una vulnerabilidad de desbordamiento de búfer de almacenamiento dinámico en la funcionalidad del servidor HTTP de Weston Embedded uC-HTTP git commit 80d4004. Un paquete de red especialmente manipulado puede provocar la ejecución de código arbitrario. Un atacante puede enviar un paquete malicioso para desencadenar esta vulnerabilidad.

20 Feb 2024, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1843', 'source': 'talos-cna@cisco.com'}

20 Feb 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-20 15:15

Updated : 2025-02-12 18:50


NVD link : CVE-2023-45318

Mitre link : CVE-2023-45318

CVE.ORG link : CVE-2023-45318


JSON object : View

Products Affected

weston-embedded

  • uc-http

silabs

  • gecko_software_development_kit
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write