CVE-2022-37398
Published on: Not Yet Published
Last Modified on: 08/11/2022 05:59:00 PM UTC
Certain versions of Adm from Asustor contain the following vulnerability:
A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected ADM versions include: 3.5.9.RUE3 and below, 4.0.5.RVI1 and below as well as 4.1.0.RJD1 and below.
- CVE-2022-37398 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
ASUSTOR - ADM version <= 3.5.9.RUE3
- Affected Vendor/Software:
ASUSTOR - ADM version <= 4.0.5.RVI1
- Affected Vendor/Software:
ASUSTOR - ADM version <= 4.1.0.RJD1
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
| ASUSTOR NAS | www.asustor.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Asustor | Adm | All | All | All | All |
Application | Asustor | Adm | All | All | All | All |
Application | Asustor | Adm | All | All | All | All |
- cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:*:
- cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:*:
- cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:*:
Discovery Credit
Nikita Abramov (Positive Technologies)
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-37398 : A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack… twitter.com/i/web/status/1… | 2022-08-05 17:06:00 |
![]() |
New Vulnerability: CVE-2022-37398 #InceptusSecure #UnderOurProtection | 2022-08-05 18:18:55 |
![]() |
Potentially Critical CVE Detected! CVE-2022-37398 A stack-based buffer overflow vulnerability was found inside ADM… twitter.com/i/web/status/1… | 2022-08-05 20:55:59 |
![]() |
CVE-2022-37398 | 2022-08-05 18:38:46 |
![]() |
ADM 4.1.0.RKM1 ( 2022-08-29 ) | 2022-08-29 11:50:42 |