CVE Feed

    Dashboard / CVE / CVE-2022-47949

    CVE-2022-47949

    The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022.

    Published:Dec 24, 2022
    Last Modified:Apr 14, 2025
    EPS:Dec 24, 2022
    EPSS Score:0.52583
    CVSS Score:9.8

    Affected Products

    Vendor
    Nintendo
    Product
    Animal Crossing\
    Vendor
    Nintendo
    Product
    Arms
    Vendor
    Nintendo
    Product
    Mario Kart 7
    Vendor
    Nintendo
    Product
    Mario Kart 8
    Vendor
    Nintendo
    Product
    Splatoon
    Vendor
    Nintendo
    Product
    Splatoon 2
    Vendor
    Nintendo
    Product
    Splatoon 3
    Vendor
    Nintendo
    Product
    Super Mario Maker 2
    Vendor
    Nintendo
    Product
    Switch Sports

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High