PT-2024-1420 · Asus · Asus Armoury Crate
Published
2024-01-18
·
Updated
2024-10-14
·
CVE-2023-5716
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ASUS Armoury Crate (affected versions not specified)
Description
The issue is related to arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission. This is due to errors in handling hyperlinks. The exploitation of this issue may allow a remote attacker to gain unauthorized access to arbitrary files.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Asus Armoury Crate