← Back to browse · API

CVE-2023-3959

Severity
CRITICAL
CVSS
9.8
EPSS
0.40396
Risk score
53.34
CISA KEV
No
PoC
No
Published
2023-11-08
Modified
2025-01-16
First seen
2026-08-07
Aliases
EUVD-2023-44584, GHSA-XW58-CRPH-CRHM
Products
Zavio:IP Camera B8220 version M2.1.6.05, Zavio:IP Camera B8520 version M2.1.6.05, Zavio:IP Camera CB3211 version M2.1.6.05, Zavio:IP Camera CB3212 version M2.1.6.05, Zavio:IP Camera CB5220 version M2.1.6.05, Zavio:IP Camera CB6231 version M2.1.6.05, Zavio:IP Camera CD321 version M2.1.6.05, Zavio:IP Camera CF7201 version M2.1.6.05, Zavio:IP Camera CF7300 version M2.1.6.05, Zavio:IP Camera CF7500 version M2.1.6.05, Zavio:IP Camera CF7501 version M2.1.6.05
Sources
euvd EUVD-2023-44584

Description

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.

References