CVE-2018-17937
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.7%
exploitation probability
2.7%top 15% of all CVEs
observed exploitation
nono source reports it
gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary code on embedded platforms via traffic on Port 2947/TCP or crafted JSON inputs.
Affected products
ICS-CERT · gpsd and microjson (Open Source Project)