PT-2022-23420 · H3C · H3C Magic Nx18 Plus

Published

2022-08-25

·

Updated

2022-08-27

·

CVE-2022-36498

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions H3C Magic NX18 Plus version NX18PV100R003
Description A stack overflow issue was discovered via the function Asp SetTimingtimeWifiAndLed. This issue affects the H3C Magic NX18 Plus device.
Recommendations For H3C Magic NX18 Plus version NX18PV100R003, consider disabling the Asp SetTimingtimeWifiAndLed function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-36498

Affected Products

H3C Magic Nx18 Plus