Vulnerability Description
An issue was discovered in WinAPRS 2.9.0. A buffer overflow in DIGI address processing for VHF KISS packets allows a remote attacker to cause a denial of service (daemon crash) via a malicious AX.25 packet over the air. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Winaprs | Winaprs | 2.9.0 |
Related Weaknesses (CWE)
References
- https://winaprs.com/ProductVendor Advisory
- https://www.coalfire.com/the-coalfire-blog/hacking-ham-radio-winaprs-part1ExploitThird Party Advisory
- https://winaprs.com/ProductVendor Advisory
- https://www.coalfire.com/the-coalfire-blog/hacking-ham-radio-winaprs-part1ExploitThird Party Advisory
FAQ
What is CVE-2022-24700?
CVE-2022-24700 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in WinAPRS 2.9.0. A buffer overflow in DIGI address processing for VHF KISS packets allows a remote attacker to cause a denial of service (daemon crash) via a malicious AX.25 p...
How severe is CVE-2022-24700?
CVE-2022-24700 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24700?
Check the references section above for vendor advisories and patch information. Affected products include: Winaprs Winaprs.