CVE-2017-9765

8.1 HIGH
Published: July 20, 2017 Modified: May 13, 2026
View on NVD

Description

Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://blog.senr.io/blog/devils-ivy-flaw-in-widely-used-third-party-code-impacts-millions
Source: cve@mitre.org
Mitigation Technical Description Third Party Advisory
http://blog.senr.io/devilsivy.html
Source: cve@mitre.org
Exploit Technical Description Third Party Advisory
http://www.securityfocus.com/bid/99868
Source: cve@mitre.org
Third Party Advisory VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1472807
Source: cve@mitre.org
Issue Tracking Third Party Advisory VDB Entry
https://bugzilla.suse.com/show_bug.cgi?id=1049348
Source: cve@mitre.org
Issue Tracking Third Party Advisory VDB Entry
https://www.genivia.com/changelog.html#Version_2.8.48_upd_%2806/21/2017%29
Source: cve@mitre.org
Release Notes Vendor Advisory
http://blog.senr.io/blog/devils-ivy-flaw-in-widely-used-third-party-code-impacts-millions
Source: af854a3a-2127-422b-91ae-364da2661108
Mitigation Technical Description Third Party Advisory
http://blog.senr.io/devilsivy.html
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Technical Description Third Party Advisory
http://www.securityfocus.com/bid/99868
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1472807
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Third Party Advisory VDB Entry
https://bugzilla.suse.com/show_bug.cgi?id=1049348
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Third Party Advisory VDB Entry
https://www.genivia.com/changelog.html#Version_2.8.48_upd_%2806/21/2017%29
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes Vendor Advisory

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
8.1 / 10.0
EPSS (Exploit Probability)
21.9%
97th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

genivia