Circutor COMPACT DC-S BASIC
Vulnerability Description
A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The device runs a CGI binary (index.cgi) to offer a management web application. Once authenticated with valid credentials in this web portal, a potential attacker could submit any "Address" value and it would be copied to a second variable with a "strcpy" vulnerable function without checking its length. Because of this, it is possible to send a long address value to overflow the process stack, controlling the function return address.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-1669
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Angel Garcia Moreno reported this vulnerability to CISA.
More from CIRCUTOR
View All →Affected Vendor
CIRCUTOR
View all reports →