#VU83475 Heap-based buffer overflow in uC-HTTP and Cesium NET - CVE-2023-27882
Published: November 24, 2023
uC-HTTP
Cesium NET
Weston Embedded
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the HTTP Server form boundary functionality. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.