CVE-2023-6249

CVSS 3.1 Score 8.0 of 10 (high)

Details

Published Feb 18, 2024
Updated: Feb 20, 2024
CWE ID 704

Summary

CVE-2023-6249 is a vulnerability affecting the esp32_ipm_send function in certain embedded systems. The issue arises due to a signed-to-unsigned conversion error, which could potentially result in buffer overflows and code injection attacks. An attacker could exploit this flaw to execute arbitrary code with elevated privileges, leading to significant security implications for affected devices. It is recommended that users apply the necessary patches or upgrades provided by the vendors to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share