Lucene search

K
cvelistTwcertCVELIST:CVE-2023-28703
HistoryJun 02, 2023 - 12:00 a.m.

CVE-2023-28703 ASUS RT-AC86U - Buffer Overflow

2023-06-0200:00:00
CWE-787
twcert
www.cve.org
asus rt-ac86u
buffer overflow
vulnerability
network packet
remote attacker
administrator
system commands
service termination

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

47.4%

ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to execute arbitrary system commands, disrupt system or terminate service.

CNA Affected

[
  {
    "vendor": "ASUS",
    "product": "RT-AC86U",
    "versions": [
      {
        "version": "3.0.0.4.386.51255",
        "status": "affected"
      }
    ]
  }
]

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

47.4%

Related for CVELIST:CVE-2023-28703