PT-2023-21356 · H3C · H3C Magic R100

Published

2023-04-07

·

Updated

2023-04-13

·

CVE-2023-27806

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions H3C Magic R100 version R100V100R005.bin
Description A stack overflow was discovered via the ipqos lanip dellist interface at the "/goform/aspForm" API endpoint. This issue allows attackers to cause a Denial of Service (DoS) via a crafted payload.
Recommendations For version R100V100R005.bin, consider disabling access to the /goform/aspForm API endpoint until a patch is available to prevent exploitation of the ipqos lanip dellist interface.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-27806

Affected Products

H3C Magic R100