CVE Vulnerabilities

CVE-2023-3749

Acceptance of Extraneous Untrusted Data With Trusted Data

Published: Aug 03, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.

Weakness

The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

Affected Software

Name Vendor Start Version End Version
Videoedge Johnsoncontrols * 6.1.1 (excluding)

References