← Back to browse · API

CVE-2020-4207

Severity
CRITICAL
CVSS
9.8
EPSS
0.04526
Risk score
40.78
CISA KEV
No
PoC
No
Published
2020-01-28
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2020-25454, GHSA-P3WR-RJ67-3CJC
Products
IBM:IoT MessageSight 2.0, IBM:IoT MessageSight 5.0.0.0, IBM:WIoTP MessageGateway 5.0.0.1
Sources
euvd EUVD-2020-25454

Description

IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP request, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause a denial of service. IBM X-Force ID: 174972.

References