CVE Vulnerabilities

CVE-2021-35394

Published: Aug 16, 2021 | Modified: Aug 08, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called MP Daemon that is usually compiled as UDPServer binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.

Affected Software

Name Vendor Start Version End Version
Realtek_jungle_sdk Realtek 2.0 (including) 3.4.14b (including)

References