CyberSec.Space Logo
CVEブラウザに戻る

CVE-2020-4207

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0980%
EPSS Percentile14.32th
Published2020年1月28日
Last Modified2024年11月21日

Vulnerability Description

IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP request, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause a denial of service. IBM X-Force ID: 174972.

Affected Platforms (CPE)

📦
Ibm

Iot Messagesight

>= 2.0.0.0 and < 2.0.0.2
📦
Ibm

Iot Messagesight

= 5.0.0.0
📦
Ibm

Watson Iot Platform Message Gateway

= 5.0.0.1

References & Advisories

関連する脆弱性情報