Executive Summary

Informations
Name CVE-2024-8947 First vendor Publication 2024-09-17
Vendor Cve Last vendor Modification 2024-09-24

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Overall CVSS Score 8.1
Base Score 8.1 Environmental Score 8.1
impact SubScore 5.9 Temporal Score 8.1
Exploitabality Sub Score 2.2
 
Attack Vector Network Attack Complexity High
Privileges Required None User Interaction None
Scope Unchanged Confidentiality Impact High
Integrity Impact High Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

A vulnerability was found in MicroPython 1.22.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file py/objarray.c. The manipulation leads to use after free. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 1.23.0 is able to address this issue. The identifier of the patch is 4bed614e707c0644c06e117f848fa12605c711cd. It is recommended to upgrade the affected component. In micropython objarray component, when a bytes object is resized and copied into itself, it may reference memory that has already been freed.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8947

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-416 Use After Free

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

Sources (Detail)

https://github.com/micropython/micropython/commit/4bed614e707c0644c06e117f848...
https://github.com/micropython/micropython/issues/13283
https://github.com/micropython/micropython/issues/13283#issuecomment-1918479709
https://github.com/micropython/micropython/releases/tag/v1.23.0
https://vuldb.com/?ctiid.277765
https://vuldb.com/?id.277765
https://vuldb.com/?submit.409316
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
Date Informations
2024-09-25 09:27:34
  • Multiple Updates
2024-09-20 17:27:28
  • Multiple Updates
2024-09-18 05:27:29
  • First insertion