---
cve: "CVE-2023-39435"
severity: "HIGH"
cvss: 8.8
epss: "1.2%"
vendor: "Zavio"
kev: false
exploited: false
published: "2023-11-08 23:15:08"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T21:17:29+02:00"
---

# CVE-2023-39435

> 8.8 HIGH

## Beschreibung

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
 CB6231, B8520, B8220, and CD321 IP Cameras 

with firmware version M2.1.6.05 are 
vulnerable to stack-based overflows. During the process of updating 
certain settings sent from incoming network requests, the product does 
not sufficiently check or validate allocated buffer size. This may lead 
to remote code execution.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-39435) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
