GHSA-j9mv-375p-293qHigh
Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image...
🔗 CVE IDs covered (1)
📋 Description
Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker with device configuration access to write attacker-controlled data outside the bounds of the process-image buffer and corrupt adjacent kernel memory, resulting in kernel memory corruption and denial of service, by supplying crafted device configuration data and crafted input through the piControl character device.