Lucene search

K
cveASUSTOR1CVE-2023-30770
HistoryApr 17, 2023 - 7:15 a.m.

CVE-2023-30770

2023-04-1707:15:08
CWE-787
ASUSTOR1
web.nvd.nist.gov
14
asustor data master
vulnerability
cve-2023-30770
buffer overflow
arbitrary code execution
security advisory

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.003

Percentile

68.6%

A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can exploit this vulnerability to execute arbitrary code. Affected ADM versions include: 4.0.6.REG2, 4.1.0 and below as well as 4.2.0.RE71 and below.

Affected configurations

Nvd
Node
asustoradmRange4.0.0.rib44.0.6.reg2
OR
asustoradmRange4.1.0.rhu24.2.1.rge2
VendorProductVersionCPE
asustoradm*cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Linux",
      "x86",
      "64 bit",
      "ARM"
    ],
    "product": "ADM",
    "vendor": "ASUSTOR",
    "versions": [
      {
        "lessThanOrEqual": "4.0.6.REG2",
        "status": "affected",
        "version": "4.0",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "4.1.0.RLQ1",
        "status": "affected",
        "version": "4.1",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "4.2.0.RE71",
        "status": "affected",
        "version": "4.2",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.003

Percentile

68.6%

Related for CVE-2023-30770