CVE-2022-27255
01.08.2022, 12:15
In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code without authentication via a crafted SIP packet that contains malicious SDP data.Enginsight
Vendor | Product | Version |
---|---|---|
realtek | ecos_rsdk_firmware | 1.5.7p1:p1 |
realtek | ecos_msdk_firmware | 4.9.4p1:p1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration