The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those function codes, the user must supply parameters. There is no sanitation on the value of the offset, which allows the client to specify any offset and read out-of-bounds data.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01 |
History
Tue, 17 Sep 2024 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | AUVESY Versiondog | AUVESY Versiondog |
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2021-10-22T11:23:37.327074Z
Updated: 2024-09-17T01:41:23.696Z
Reserved: 2021-08-10T00:00:00
Link: CVE-2021-38451
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-10-22T12:15:08.130
Modified: 2024-11-21T06:17:07.850
Link: CVE-2021-38451
Redhat
No data.