CVE-2024-23621

A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:merge_efilm_workstation:*:*:*:*:*:*:*:*

History

31 Jan 2024, 20:30

Type Values Removed Values Added
References () https://blog.exodusintel.com/2024/01/25/ibm-merge-healthcare-efilm-workstation-license-server-buffer-overflow/ - () https://blog.exodusintel.com/2024/01/25/ibm-merge-healthcare-efilm-workstation-license-server-buffer-overflow/ - Third Party Advisory
First Time Ibm
Ibm merge Efilm Workstation
CPE cpe:2.3:a:ibm:merge_efilm_workstation:*:*:*:*:*:*:*:*
CVSS v2 : 10.0
v3 : 10.0
v2 : 10.0
v3 : 9.8
CWE CWE-120

26 Jan 2024, 13:51

Type Values Removed Values Added
Summary
  • (es) Existe un desbordamiento de búfer en el servidor de licencias de IBM Merge Healthcare eFilm Workstation. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para lograr la ejecución remota de código.

26 Jan 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-26 00:15

Updated : 2024-01-31 20:30


NVD link : CVE-2024-23621

Mitre link : CVE-2024-23621

CVE.ORG link : CVE-2024-23621


JSON object : View

Products Affected

ibm

  • merge_efilm_workstation
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CWE-131

Incorrect Calculation of Buffer Size