CVE-2023-6249
CVSS 3.1 Score 8.0 of 10 (high)
Details
Published Feb 18, 2024
Updated: Feb 20, 2024
CWE ID 704
Summary
CVE-2023-6249 is a vulnerability affecting the esp32_ipm_send function in certain embedded systems. The issue arises due to a signed-to-unsigned conversion error, which could potentially result in buffer overflows and code injection attacks. An attacker could exploit this flaw to execute arbitrary code with elevated privileges, leading to significant security implications for affected devices. It is recommended that users apply the necessary patches or upgrades provided by the vendors to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share