Lucene search

K
cveMitreCVE-2013-6343
HistoryJan 22, 2014 - 5:22 a.m.

CVE-2013-6343

2014-01-2205:22:12
CWE-119
mitre
web.nvd.nist.gov
35
cve-2013-6343
buffer overflow
httpd
asus routers
remote code execution
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

Low

EPSS

0.192

Percentile

96.3%

Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_flag parameter to APP_Installation.asp.

Affected configurations

Nvd
Node
asustm-ac1900_firmwareMatch3.0.0.4..374_979
AND
asustm-ac1900Match-
Node
asusrt-n56u_firmwareMatch3.0.0.4..374_979
AND
asusrt-n56uMatch-
Node
asusrt-ac66u_firmwareMatch3.0.0.4..374_979
AND
asusrt-ac66uMatch-
VendorProductVersionCPE
asustm-ac1900_firmware3.0.0.4..374_979cpe:2.3:o:asus:tm-ac1900_firmware:3.0.0.4..374_979:*:*:*:*:*:*:*
asustm-ac1900-cpe:2.3:h:asus:tm-ac1900:-:*:*:*:*:*:*:*
asusrt-n56u_firmware3.0.0.4..374_979cpe:2.3:o:asus:rt-n56u_firmware:3.0.0.4..374_979:*:*:*:*:*:*:*
asusrt-n56u-cpe:2.3:h:asus:rt-n56u:-:*:*:*:*:*:*:*
asusrt-ac66u_firmware3.0.0.4..374_979cpe:2.3:o:asus:rt-ac66u_firmware:3.0.0.4..374_979:*:*:*:*:*:*:*
asusrt-ac66u-cpe:2.3:h:asus:rt-ac66u:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

Low

EPSS

0.192

Percentile

96.3%