Vulnerability Intelligence Report
CVE-2022-27255
In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code without authentication via a crafted SIP packet that contains malicious SDP data.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:37.08%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| realtek | ecos_rsdk_firmware | 1.5.7p1 |
| realtek | ecos_rsdk | all |
| realtek | ecos_msdk_firmware | 4.9.4p1 |
| realtek | ecos_msdk | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
37.080%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2022-03-20T00:00:00 |
| Published | 2022-08-01T11:43:25 |
| Last Updated | 2024-08-03T05:25:32 |
Community Chatter & Buzz