CVE-2022-24700 describes a buffer overflow vulnerability in WinAPRS 2.9.0, specifically within its DIGI address processing for VHF KISS packets. A remote attacker can exploit this by sending a malicious AX.25 packet over the air, leading to a denial of service (daemon crash). This vulnerability is rated as High severity (CVSS 7.5), indicating it can be exploited remotely with low complexity and without user interaction, resulting in high impact to availability. While the vulnerability is significant, it affects an unsupported product and currently lacks public exploit code, Metasploit modules, or any community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.9.0CPE matchmatch criteria | cpe:2.3:a:winaprs:winaprs:2.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.