CVE-2022-38693
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.8%
exploitation probability
0.8%top 48% of all CVEs
observed exploitation
nono source reports it
In short
FDL1 fails to check the size of incoming data before storing it in memory, allowing an attacker to overflow a buffer and potentially crash the system or execute malicious code.
Technical detail
A missing payload size validation in FDL1 permits an unauthenticated network attacker to trigger a stack or heap buffer overflow by sending oversized data, potentially achieving remote code execution without elevated privileges.
Summary generated and translated by AI from the official description.
In FDL1, there is a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H