Lucene search

K
nvd[email protected]NVD:CVE-2023-30770
HistoryApr 17, 2023 - 7:15 a.m.

CVE-2023-30770

2023-04-1707:15:08
CWE-787
web.nvd.nist.gov
2
cve-2023-30770
data size validation
arbitrary code execution
asustor data master
affected versions

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8

Confidence

High

EPSS

0.003

Percentile

68.6%

A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can exploit this vulnerability to execute arbitrary code. Affected ADM versions include: 4.0.6.REG2, 4.1.0 and below as well as 4.2.0.RE71 and below.

Affected configurations

Nvd
Node
asustoradmRange4.0.0.rib44.0.6.reg2
OR
asustoradmRange4.1.0.rhu24.2.1.rge2
VendorProductVersionCPE
asustoradm*cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8

Confidence

High

EPSS

0.003

Percentile

68.6%

Related for NVD:CVE-2023-30770