Vulnerabilities > CVE-2023-6322 - Out-of-bounds Write vulnerability in multiple products

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
wyze
roku
throughtek
CWE-787

Summary

A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A specially crafted message can lead to stack-based buffer overflow. An attacker can make authenticated requests to trigger this vulnerability.

Vulnerable Configurations

Part Description Count
OS
Wyze
1
OS
Roku
1
Hardware
Wyze
1
Hardware
Roku
1
Application
Throughtek
1

Common Weakness Enumeration (CWE)