Vulnerability Details CVE-2023-45225
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321
IP Cameras with firmware version M2.1.6.05 are
vulnerable to multiple instances of stack-based overflows. While parsing
certain XML elements from incoming network requests, the product does
not sufficiently check or validate allocated buffer size. This may lead
to remote code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-45225
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:o:zavio:b8220_firmware:m2.1.6.05
-
cpe:2.3:o:zavio:b8520_firmware:m2.1.6.05
-
cpe:2.3:o:zavio:cb3211_firmware:m2.1.6.05
-
cpe:2.3:o:zavio:cb3212_firmware:m2.1.6.05
-
cpe:2.3:o:zavio:cb5220_firmware:m2.1.6.05
-
cpe:2.3:o:zavio:cb6231_firmware:m2.1.6.05
-
cpe:2.3:o:zavio:cd321_firmware:m2.1.6.05
-
cpe:2.3:o:zavio:cf7201_firmware:m2.1.6.05
-
cpe:2.3:o:zavio:cf7300_firmware:m2.1.6.05
-
cpe:2.3:o:zavio:cf7500_firmware:m2.1.6.05
-
cpe:2.3:o:zavio:cf7501_firmware:m2.1.6.05