CVE-2023-2909
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
31/05/2023
Last modified:
07/06/2023
Description
EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.
Impact
Base Score 3.x
10.00
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* | 4.0.0 (including) | 4.0.6.reg2 (including) |
| cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* | 4.1.0 (including) | 4.1.0rlq1 (including) |
| cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* | 4.2.0 (including) | 4.2.1.rge2 (including) |
To consult the complete list of CPE names with products and versions, see this page



