VDB

CVE-2022-25147

CVE-2022-25147 PUBLISHED CVSS 6.5 MEDIUM

Apache portable runtime utility issue may allow a malicious attacker to cause an out-of-bounds write due to an integer overflow when encoding/decoding a very long string using the base64 family of functions. This could lead to modification of data or denial of service.

EPSS 1.42% · 71.7th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:W/RC:C
EPSS Score
1.42%
71.7th percentile

Affected Products

VendorProductVersions
ABBABB M2M Gateway SW, software versions >=5.0.1|<=5.0.3
ABBABB M2M Gateway ARM600, firmware versions >=4.1.2|<=5.0.3

Timeline

  • Jan 31, 2023 CVE Published
  • Feb 1, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 12, 2023 EPSS Score
  • Apr 15, 2023 EPSS Score
  • Apr 23, 2023 EPSS Score
  • May 18, 2023 EPSS Score
  • Jun 3, 2023 EPSS Score
  • Aug 23, 2023 EPSS Score
  • Oct 3, 2023 EPSS Score
  • Nov 12, 2023 EPSS Score
  • Dec 23, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›