The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those function codes, the user must supply parameters. There is no sanitation on the value of the offset, which allows the client to specify any offset and read out-of-bounds data.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01 |     | 
History
                    Tue, 17 Sep 2024 01:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | AUVESY Versiondog | AUVESY Versiondog | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: icscert
Published: 2021-10-22T11:23:37.327074Z
Updated: 2024-09-17T01:41:23.696Z
Reserved: 2021-08-10T00:00:00
Link: CVE-2021-38451
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2021-10-22T12:15:08.130
Modified: 2024-11-21T06:17:07.850
Link: CVE-2021-38451
 Redhat
                        Redhat
                    No data.