CVE-2024-50697

In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not have sufficient bounds checks. This may result in a stack-based buffer overflow.
Configurations

No configuration.

History

27 Jan 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) En SunGrow WiNet-SV200.001.00.P027 y versiones anteriores, al descifrar mensajes MQTT, el código que analiza campos TLV específicos no tiene suficientes comprobaciones de los límites. Esto puede provocar un desbordamiento del búfer basado en la pila.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CWE CWE-120

24 Jan 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-24 23:15

Updated : 2025-01-27 16:15


NVD link : CVE-2024-50697

Mitre link : CVE-2024-50697

CVE.ORG link : CVE-2024-50697


JSON object : View

Products Affected

No product.

CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')