60
CVE-2023-47610
—CVSS 3.1
9.8 critical
EPSS
2%p76
Published
()
Modified
Description
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists in Telit Cinterion EHS5/6/8 that could allow a remote unauthenticated attacker to execute arbitrary code on the targeted system by sending a specially crafted SMS message.
- Vendors
- telit
- Products
- bgs5 firmware, ehs5 firmware, ehs6 firmware, ehs8 firmware, pds5 firmware, pds6 firmware, pds8 firmware, els61 firmware, els81 firmware, pls62 firmware
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H