Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9f6-cwjv-332v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Service configuration-1 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

The Service configuration-1 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

EPSS

Процентиль: 75%
0.00895
Низкий

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 4.9
nvd
почти 5 лет назад

The Service configuration-1 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

EPSS

Процентиль: 75%
0.00895
Низкий

Дефекты

CWE-120