A vulnerability, which was classified as problematic, was found in FabulaTech USB over Network 6.0.6.1. This affects the function 0x220448 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link | Resource |
---|---|
https://shareforall.notion.site/FabulaTech-USB-over-Network-Client-ftusbbus2-0x220448-NPD-DOS-15160437bb1e80cb837cd715680be6ea | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.288525 | Permissions Required VDB Entry |
https://vuldb.com/?id.288525 | Permissions Required VDB Entry |
https://vuldb.com/?submit.456030 | Third Party Advisory VDB Entry |
Configurations
History
19 Dec 2024, 15:11
Type | Values Removed | Values Added |
---|---|---|
CWE | ||
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
First Time |
Fabulatech
Fabulatech usb Over Network |
|
CPE | cpe:2.3:a:fabulatech:usb_over_network:6.0.6.1:*:*:*:*:*:*:* | |
References | () https://vuldb.com/?submit.456030 - Third Party Advisory, VDB Entry | |
References | () https://shareforall.notion.site/FabulaTech-USB-over-Network-Client-ftusbbus2-0x220448-NPD-DOS-15160437bb1e80cb837cd715680be6ea - Exploit, Third Party Advisory | |
References | () https://vuldb.com/?id.288525 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?ctiid.288525 - Permissions Required, VDB Entry |
16 Dec 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-16 17:15
Updated : 2024-12-19 15:11
NVD link : CVE-2024-12656
Mitre link : CVE-2024-12656
JSON object : View
Products Affected
fabulatech
- usb_over_network
CWE
CWE-476
NULL Pointer Dereference