CVE-2023-0847 is an out-of-bounds write vulnerability affecting the Sub-IoT implementation of the DASH 7 Alliance protocol, specifically versions prior to 0.5.0. This high-severity vulnerability (CVSS 8.1) can lead to system crashes and remote code execution if the protocol was configured with non-default settings, although default settings only expose allocated but unused memory. Currently, there is no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.5.0CPE matchmatch criteria | cpe:2.3:a:dash7-alliance:dash7_alliance_protcol:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.