CVE-2023-7158 is a critical heap-based buffer overflow vulnerability affecting MicroPython versions up to 1.21.0, specifically within the slice_indices function in objslice.c. This flaw allows for remote exploitation, potentially leading to complete compromise of confidentiality, integrity, and availability, as reflected by its CVSS score of 9.8. While a public exploit has been disclosed, there is no evidence of active exploitation, and it currently lacks widespread community discussion or media coverage. Organizations using affected MicroPython versions are strongly advised to upgrade to version 1.22.0 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.22.0CPE matchmatch criteria | cpe:2.3:a:micropython:micropython:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.