47
CVE-2022-43974
—CVSS 3.1
9.8 critical
EPSS
2%p76
Published
()
Modified
Description
MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13. A remote attacker might be able to send a crafted TLS Message to cause a buffer overflow and achieve remote code execution. This is fixed in 4.6.0.
- Vendors
- matrixssl
- Products
- matrixssl
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H