Aller au contenu

Fiche vulnérabilité

CVE-2022-27255 : faille critique realtek ecos rsdk firmware (CVSS 9.8)

Description

In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code without authentication via a crafted SIP packet that contains malicious SDP data.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
1 août 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • realtek ecos rsdk firmware
  • realtek ecos msdk firmware

Références

Rechercher une autre vulnérabilité dans la base CVE