CVE-2024-40723

The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the length of server-side inputs. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the HWATAIServiSign, temporarily disrupting its service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:changingtec:hwatai_servisign:*:*:*:*:*:windows:*:*

History

09 Aug 2024, 14:44

Type Values Removed Values Added
CWE CWE-787
CPE cpe:2.3:a:changingtec:hwatai_servisign:*:*:*:*:*:windows:*:*
References () https://www.twcert.org.tw/en/cp-139-7974-0562f-2.html - () https://www.twcert.org.tw/en/cp-139-7974-0562f-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-7968-ce2ef-1.html - () https://www.twcert.org.tw/tw/cp-132-7968-ce2ef-1.html - Third Party Advisory
First Time Changingtec
Changingtec hwatai Servisign

02 Aug 2024, 12:59

Type Values Removed Values Added
Summary
  • (es) La API específica en HWATAIServiSign Windows Version de CHANGING Information Technology no valida correctamente la longitud de las entradas del lado del servidor. Cuando un usuario visita un sitio web falsificado, atacantes remotos no autenticados pueden provocar un desbordamiento de búfer en la región stack de la memoria en HWATAIServiSign, interrumpiendo temporalmente su servicio.

02 Aug 2024, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-02 11:16

Updated : 2024-08-09 14:44


NVD link : CVE-2024-40723

Mitre link : CVE-2024-40723

CVE.ORG link : CVE-2024-40723


JSON object : View

Products Affected

changingtec

  • hwatai_servisign
CWE
CWE-787

Out-of-bounds Write

CWE-121

Stack-based Buffer Overflow