VDB

CVE-2023-7158

CVE-2023-7158 PUBLISHED CVSS 7.300000190734863 HIGH

A vulnerability was found in MicroPython up to 1.21.0. It has been classified as critical. Affected is the function slice_indices of the file objslice.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.22.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-249180.

EPSS 1.23% · 66.0th percentile

Risk Scores

CVSS 3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
1.23%
66.0th percentile

Affected Products

VendorProductVersions
n/aMicroPython1.21.0, 1.13.0, 1.14.0
micropythonmicropython0

Timeline

  • Jan 20, 1970 Fix PR Merged
  • Jan 20, 1970 Fix PR Merged
  • Dec 29, 2023 EPSS Score
  • Dec 29, 2023 CVE Published
  • Jan 27, 2024 EPSS Score
  • Feb 24, 2024 EPSS Score
  • Apr 22, 2024 EPSS Score
  • May 21, 2024 EPSS Score
  • Jun 18, 2024 EPSS Score
  • Jul 17, 2024 EPSS Score
  • Aug 15, 2024 EPSS Score
  • Sep 13, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›