CVE Vulnerabilities

CVE-2023-27748

Insufficient Verification of Data Authenticity

Published: Apr 13, 2023 | Modified: Apr 25, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Dr750-2ch_lte_firmware Blackvue 1.012_2022.10.26 (including) 1.012_2022.10.26 (including)

References