A heap-based buffer overflow in a network service in Fastweb FASTGate MediaAccess FGA2130FWB, firmware version 18.3.n.0482_FW_230_FGA2130, and DGA4131FWB, firmware version up to 18.3.n.0462_FW_261_DGA4131, allows a remote attacker to reboot the device through a crafted HTTP request, causing DoS.
References
Link | Resource |
---|---|
https://str0ng4le.github.io/jekyll/update/2023/05/12/fastgate-bof-cve-2022-30114/ | Exploit Technical Description Third Party Advisory |
https://www.fastweb.it/myfastweb/assistenza/guide/FASTGate/ |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
21 Sep 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
20 Sep 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
26 May 2023, 18:07
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
First Time |
Fastweb fastgate Vdsl2 Dga4131fwb
Fastweb Fastweb fastgate Gpon Fga2130fwb Fastweb fastgate Gpon Fga2130fwb Firmware Fastweb fastgate Vdsl2 Dga4131fwb Firmware |
|
CPE | cpe:2.3:o:fastweb:fastgate_gpon_fga2130fwb_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:fastweb:fastgate_gpon_fga2130fwb:-:*:*:*:*:*:*:* cpe:2.3:h:fastweb:fastgate_vdsl2_dga4131fwb:-:*:*:*:*:*:*:* cpe:2.3:o:fastweb:fastgate_vdsl2_dga4131fwb_firmware:*:*:*:*:*:*:*:* |
|
CWE | CWE-787 | |
References | (MISC) https://str0ng4le.github.io/jekyll/update/2023/05/12/fastgate-bof-cve-2022-30114/ - Exploit, Technical Description, Third Party Advisory | |
References | (MISC) http://fastgate.com - Broken Link | |
References | (MISC) http://fastweb.com - Broken Link |
Information
Published : 2023-05-19 12:15
Updated : 2024-02-28 20:13
NVD link : CVE-2022-30114
Mitre link : CVE-2022-30114
CVE.ORG link : CVE-2022-30114
JSON object : View
Products Affected
fastweb
- fastgate_gpon_fga2130fwb
- fastgate_vdsl2_dga4131fwb_firmware
- fastgate_gpon_fga2130fwb_firmware
- fastgate_vdsl2_dga4131fwb
CWE
CWE-787
Out-of-bounds Write