← Back to browse · API

CVE-2023-28753

Severity
CRITICAL
CVSS
9.8
EPSS
0.01851
Risk score
39.85
CISA KEV
No
PoC
No
Published
2023-05-18
Modified
2025-01-21
First seen
2026-08-07
Aliases
EUVD-2023-32391, GHSA-C9C6-6QVF-4M65
Products
Facebook:netconsd 0.0 <0.2
Sources
euvd EUVD-2023-32391

Description

netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to create heap memory corruption with attacker controlled data.

References