CVE-2017-2921
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause an integer overflow, leading to a heap buffer overflow and resulting in denial of service and potential remote code execution. An attacker needs to send a specially crafted websocket packet over network to trigger this vulnerability.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.42% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- cesanta/mongoose
- Source
- talos-cna@cisco.com
References
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0428Exploit, Technical Description, Third Party Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0428Exploit, Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.