CVE-2024-43770
published 2025-01-21CVE-2024-43770: In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent)…
PriorityP350high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.22%
12.6th percentile
In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_modules_bluetooth | >= 13:0 < 13:2025-01-01 | 13:2025-01-01 |
| platform | packages_modules_bluetooth | >= 14:0 < 14:2025-01-01 | 14:2025-01-01 |
| platform | packages_modules_bluetooth | >= 15-next:0 < 15-next:2025-01-01 | 15-next:2025-01-01 |
| platform | packages_modules_bluetooth | >= 15:0 < 15:2025-01-01 | 15:2025-01-01 |
| platform | system_bt | >= 12:0 < 12:2025-01-01 | 12:2025-01-01 |
| platform | system_bt | >= 12L:0 < 12L:2025-01-01 | 12L:2025-01-01 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cisa6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Liferay Portal vulnerable to Reflected XSS with the referer and forward parameter
ghsa·2025-08-23
CVE-2025-43770 [MEDIUM] CWE-79 Liferay Portal vulnerable to Reflected XSS with the referer and forward parameter
Liferay Portal vulnerable to Reflected XSS with the referer and forward parameter
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the referer or FORWARD_URL using %00 in those parameters.
GHSA
GHSA-fq6x-64vf-73q4: In gatts_process_find_info of gatt_sr
ghsa_unreviewed·2025-01-22
CVE-2024-43770 [HIGH] CWE-787 GHSA-fq6x-64vf-73q4: In gatts_process_find_info of gatt_sr
In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-43770: In gatts_process_find_info of gatt_sr
osv·2025-01-01
CVE-2024-43770 CVE-2024-43770: In gatts_process_find_info of gatt_sr
In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2024-43770: Android Security Bulletin 2025-01-01
CVE: CVE-2024-43770
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 12, 12L, 13, 14, 15
References: A-364026
vendor_android·2025-01-01·CVSS 8.8
CVE-2024-43770 [HIGH] CVE-2024-43770: Android Security Bulletin 2025-01-01
CVE: CVE-2024-43770
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 12, 12L, 13, 14, 15
References: A-364026
Android Security Bulletin 2025-01-01
CVE: CVE-2024-43770
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 12, 12L, 13, 14, 15
References: A-364026473
CISA
Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
cisa·2024-02-12·CVSS 6.1
CVE-2023-43770 [MEDIUM] CWE-79 Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
Vulnerability: Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
Affected: Roundcube Webmail
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://roundcube.net/news/2023/09/15/security-update-1.6.3-released ; https://nvd.nist.gov/vuln/detail/CVE-2023-43770
Remediation Due Date: 2024-03-04
Suricata
ET EXPLOIT RoundCube Webmail Persistent XSS Attempt (CVE-2023-43770)
suricata·2024-03-28·CVSS 6.1
CVE-2023-43770 [MEDIUM] ET EXPLOIT RoundCube Webmail Persistent XSS Attempt (CVE-2023-43770)
ET EXPLOIT RoundCube Webmail Persistent XSS Attempt (CVE-2023-43770)
Rule: alert smtp any any -> [$SMTP_SERVERS,$HOME_NET] any (msg:"ET EXPLOIT RoundCube Webmail Persistent XSS Attempt (CVE-2023-43770)"; flow:established,to_server; content:"Content-Type: text/plain|3b|"; content:"|0a 0a 5b 3c|"; fast_pattern; pcre:"/^[^\x3e\x0d\x0a]*?(?:[\x20\x27\x22\x2f]on[a-z]+\x3d|(?:\x3cs(?:cript[\x3a\x3e\x20\x2b\x2f]|tyle\x3d)|\x3ciframe[\x20\x2f]))/R"; reference:cve,2023-43770; classtype:attempted-user; sid:2051827; rev:2; metadata:attack_target Networking_Equipment, created_at 2024_03_28, cve CVE_2023_43770, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2026_01_14;)
No public exploits indexed.
No writeups or analysis indexed.
2025-01-21
Published