Stack buffer overflow in method gdv-serverconfig
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.5%
exploitation probability
0.5%top 62% of all CVEs
observed exploitation
nono source reports it
In short
A user can send specially crafted data to gdv-serverconfig that overflows a memory buffer on the stack, allowing them to take complete control of the system with root privileges.
Technical detail
Stack buffer overflow in gdv-serverconfig (CWE-121) allows an authenticated attacker to overwrite stack memory and execute arbitrary code with root privileges. The vulnerability requires valid user credentials and can be triggered by supplying oversized input to the affected method, bypassing security restrictions.
Summary generated and translated by AI from the official description.
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
MBS · Double-A ProfibusMBS · Double-A x-linkMBS · Double-X CANMBS · Double-X DALIMBS · Double-X KNXMBS · Double-X LONMBS · Double-X M-BusMBS · Double-X PROFINETMBS · Double-X x-linkMBS · Single-AMBS · Single-XMBS · Triple-X KNX+DALIMBS · Triple-X KNX+LONMBS · Triple-X KNX+M-BusMBS · Triple-X PROFINET+DALIMBS · Triple-X PROFINET+KNXMBS · Triple-X PROFINET+LONMBS · Triple-X PROFINET+M-Bus