Use of Externally-Controlled Format String
CVE-2023-21420
Summary
Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.
- LOW
- LOCAL
- HIGH
- UNCHANGED
- NONE
- LOW
- LOW
- HIGH
CWE-134 - Use of Externally-Controlled Format String
The software uses a function that accepts a format string as an argument, but the format string originates from an external source.
References
Advisory Timeline
- Published