// For flags

CVE-2023-48221

wire-avs remote format string vulnerability

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

wire-avs provides Audio, Visual, and Signaling (AVS) functionality sure the secure messaging software Wire. Prior to versions 9.2.22 and 9.3.5, a remote format string vulnerability could potentially allow an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs 9.2.22 & 9.3.5 and is already included on all Wire products. No known workarounds are available.

wire-avs proporciona funcionalidad de Audio, Visual, and Signaling (AVS) en el software de mensajería segura Wire. Antes de las versiones 9.2.22 y 9.3.5, una vulnerabilidad de cadena de formato remoto podría permitir a un atacante provocar una Denegación de Servicio o posiblemente ejecutar código arbitrario. El problema se solucionó en wire-avs 9.2.22 y 9.3.5 y ya está incluido en todos los productos Wire. No hay workarounds conocidos disponibles.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-11-13 CVE Reserved
  • 2023-11-20 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-09-26 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-134: Use of Externally-Controlled Format String
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Wire
Search vendor "Wire"
Audio\, Video\, And Signaling
Search vendor "Wire" for product "Audio\, Video\, And Signaling"
< 9.2.22
Search vendor "Wire" for product "Audio\, Video\, And Signaling" and version " < 9.2.22"
-
Affected
Wire
Search vendor "Wire"
Audio\, Video\, And Signaling
Search vendor "Wire" for product "Audio\, Video\, And Signaling"
>= 9.3.0 <= 9.3.5
Search vendor "Wire" for product "Audio\, Video\, And Signaling" and version " >= 9.3.0 <= 9.3.5"
-
Affected