CVE-2023-2909

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
31/05/2023
Last modified:
07/06/2023

Description

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* 4.0.0 (including) 4.0.6.reg2 (including)
cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* 4.1.0 (including) 4.1.0rlq1 (including)
cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* 4.2.0 (including) 4.2.1.rge2 (including)


References to Advisories, Solutions, and Tools