CVE-2023-41349: falha de alta gravidade em ASUS RT-AX88U
ASUS RT-AX88U - externally-controlled format string
Publicada em · Atualizada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.8epss 0.9%
probabilidade de exploração
0.9%top 43% das CVEs
exploração observada
nãonenhuma fonte reporta
ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
ASUS · RT-AX88UCVEs relacionadas — ASUS RT-AX88U
No mesmo produto, das mais perigosas para as menos.
CVE-2024-3080CRITICALASUS Router - Improper AuthenticationEPSS 43.5%CVE-2022-26674CRITICALASUS RT-AX88U - Format StringEPSS 2.8%CVE-2024-3079HIGHASUS Router - Stack-based Buffer OverflowEPSS 0.8%CVE-2023-34359HIGHASUS RT-AX88U - Out-of-bounds Read - 2EPSS 0.8%CVE-2023-34358HIGHASUS RT-AX88U - Out-of-bounds Read - 1EPSS 0.8%CVE-2024-0401HIGHASUS OVPN RCEEPSS 0.7%