THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-21778

Assignertalos
Reserved2024-01-10
Published2024-07-08
Updated2024-07-13

Description

A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted .dat file can lead to arbitrary code execution. An attacker can upload a malicious file to trigger this vulnerability.



HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-122: Heap-based Buffer Overflow

Product status

RER4_A_v3411b_2T2R_LEV_09_170623
affected

v3.4.11
affected

Credits

Discovered by Francesco Benvenuto and Kelly Patterson of Cisco Talos.

References

https://talosintelligence.com/vulnerability_reports/TALOS-2024-1911

cve.org CVE-2024-21778

nvd.nist.gov CVE-2024-21778

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-21778
© Copyright 2024 THREATINT. Made in Cyprus with +