{"api_version":"1","generated_at":"2026-07-23T11:22:46+00:00","cve":"CVE-2023-2870","urls":{"html":"https://cve.report/CVE-2023-2870","api":"https://cve.report/api/cve/CVE-2023-2870.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-2870","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-2870"},"summary":{"title":"CVE-2023-2870","description":"A vulnerability was found in EnTech Monitor Asset Manager 2.9. It has been declared as problematic. Affected by this vulnerability is the function 0x80002014 of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier VDB-229849 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2023-05-24 18:15:00","updated_at":"2023-11-07 04:13:00"},"problem_types":["CWE-404"],"metrics":[],"references":[{"url":"https://drive.google.com/file/d/1ehTYhcdeTiB4rQ38n5FqhQZgVqcvvPE_/view?usp=sharing","name":"https://drive.google.com/file/d/1ehTYhcdeTiB4rQ38n5FqhQZgVqcvvPE_/view?usp=sharing","refsource":"MISC","tags":[],"title":"DoS.zip - Google Drive","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://vuldb.com/?id.229849","name":"https://vuldb.com/?id.229849","refsource":"MISC","tags":[],"title":"CVE-2023-2870: EnTech Monitor Asset Manager IoControlCode 0x80002014 denial of service","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/zeze-zeze/WindowsKernelVuln/tree/master/unassigned47","name":"https://github.com/zeze-zeze/WindowsKernelVuln/tree/master/unassigned47","refsource":"MISC","tags":[],"title":"WindowsKernelVuln/unassigned47 at master · zeze-zeze/WindowsKernelVuln · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/zeze-zeze/WindowsKernelVuln/blob/master/CVE-2023-2870","name":"https://github.com/zeze-zeze/WindowsKernelVuln/blob/master/CVE-2023-2870","refsource":"MISC","tags":[],"title":"WindowsKernelVuln/CVE-2023-2870 at master · zeze-zeze/WindowsKernelVuln · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://vuldb.com/?ctiid.229849","name":"https://vuldb.com/?ctiid.229849","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-2870","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-2870","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"2870","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"entechtaiwan","cpe5":"monitor_asset_manager","cpe6":"2.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-2870","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A vulnerability was found in EnTech Monitor Asset Manager 2.9. It has been declared as problematic. Affected by this vulnerability is the function 0x80002014 of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier VDB-229849 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way."},{"lang":"deu","value":"In EnTech Monitor Asset Manager 2.9 wurde eine problematische Schwachstelle ausgemacht. Hierbei betrifft es die Funktion 0x80002014 der Komponente IoControlCode Handler. Durch Manipulation mit unbekannten Daten kann eine denial of service-Schwachstelle ausgenutzt werden. Der Angriff muss lokal angegangen werden. Der Exploit steht zur öffentlichen Verfügung."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-404 Denial of Service","cweId":"CWE-404"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"EnTech","product":{"product_data":[{"product_name":"Monitor Asset Manager","version":{"version_data":[{"version_affected":"=","version_value":"2.9"}]}}]}}]}},"references":{"reference_data":[{"url":"https://vuldb.com/?id.229849","refsource":"MISC","name":"https://vuldb.com/?id.229849"},{"url":"https://vuldb.com/?ctiid.229849","refsource":"MISC","name":"https://vuldb.com/?ctiid.229849"},{"url":"https://github.com/zeze-zeze/WindowsKernelVuln/blob/master/CVE-2023-2870","refsource":"MISC","name":"https://github.com/zeze-zeze/WindowsKernelVuln/blob/master/CVE-2023-2870"},{"url":"https://drive.google.com/file/d/1ehTYhcdeTiB4rQ38n5FqhQZgVqcvvPE_/view?usp=sharing","refsource":"MISC","name":"https://drive.google.com/file/d/1ehTYhcdeTiB4rQ38n5FqhQZgVqcvvPE_/view?usp=sharing"}]},"credits":[{"lang":"en","value":"Zeze7w (VulDB User)"}],"impact":{"cvss":[{"version":"3.1","baseScore":3.3,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseSeverity":"LOW"},{"version":"3.0","baseScore":3.3,"vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseSeverity":"LOW"},{"version":"2.0","baseScore":1.7,"vectorString":"AV:L/AC:L/Au:S/C:N/I:N/A:P"}]}},"nvd":{"publishedDate":"2023-05-24 18:15:00","lastModifiedDate":"2023-11-07 04:13:00","problem_types":["CWE-404"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:entechtaiwan:monitor_asset_manager:2.9:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}