VDB

CVE-2022-25147

CVE-2022-25147 PUBLISHED CVSS 6.5 MEDIUM

Apache portable runtime utility issue may allow a malicious attacker to cause an out-of-bounds write due to an integer overflow when encoding/decoding a very long string using the base64 family of functions. This could lead to modification of data or denial of service.

EPSS 0.06% · 18.8th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:W/RC:C
EPSS Score
0.06%
18.8th percentile

Affected Products

VendorProductVersions
ABBABB M2M Gateway SW, software versions >=5.0.1|<=5.0.3
ABBABB M2M Gateway ARM600, firmware versions >=4.1.2|<=5.0.3

Timeline

  • Jan 31, 2023 CVE Published
  • Feb 1, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 12, 2023 EPSS Score
  • Apr 15, 2023 EPSS Score
  • Apr 22, 2023 EPSS Score
  • May 18, 2023 EPSS Score
  • Jun 1, 2023 EPSS Score
  • Jul 12, 2023 EPSS Score
  • Sep 30, 2023 EPSS Score
  • Nov 9, 2023 EPSS Score
  • Dec 19, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›