CVE-2022-27255

In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code without authentication via a crafted SIP packet that contains malicious SDP data.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:realtek:ecos_rsdk_firmware:1.5.7p1:*:*:*:*:*:*:*
cpe:2.3:h:realtek:ecos_rsdk:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:realtek:ecos_msdk_firmware:4.9.4p1:*:*:*:*:*:*:*
cpe:2.3:h:realtek:ecos_msdk:-:*:*:*:*:*:*:*

Information

Published : 2022-08-01 05:15

Updated : 2022-09-30 12:49


NVD link : CVE-2022-27255

Mitre link : CVE-2022-27255


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

realtek

  • ecos_rsdk
  • ecos_msdk
  • ecos_rsdk_firmware
  • ecos_msdk_firmware