PT-2024-1420 · Asus · Asus Armoury Crate

Published

2024-01-18

·

Updated

2024-10-14

·

CVE-2023-5716

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASUS Armoury Crate (affected versions not specified)
Description The issue is related to arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission. This is due to errors in handling hyperlinks. The exploitation of this issue may allow a remote attacker to gain unauthorized access to arbitrary files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-00893
CVE-2023-5716

Affected Products

Asus Armoury Crate