CVE-2023-39540
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within the parsing an IPv4 ICMP packet.
Existe una vulnerabilidad de denegación de servicio en la funcionalidad de análisis ICMP e ICMPv6 de Weston Embedded uC-TCP-IP v3.06.01. Un paquete de red especialmente manipulado puede provocar una lectura fuera de los límites. Un atacante puede enviar un paquete malicioso para desencadenar esta vulnerabilidad. Esta vulnerabilidad se refiere a una denegación de servicio durante el análisis de un paquete ICMP IPv4.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-08-03 CVE Reserved
- 2024-02-20 CVE Published
- 2024-08-02 CVE Updated
- 2025-02-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-126: Buffer Over-read
CAPEC
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Silicon Labs Search vendor "Silicon Labs" | Gecko Platform Search vendor "Silicon Labs" for product "Gecko Platform" | 4.3.1.0 Search vendor "Silicon Labs" for product "Gecko Platform" and version "4.3.1.0" | en |
Affected
|