Medium6.1
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N

PT-2022-06: Stack-based buffer overflow in ASUSTOR Data Master (ADM)

Error type:

  • CWE-121:Stack-based Buffer Overflow

Vulnerability vector:

  • Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
  • Severity (CVSSv3.1): 7.1 (high)
  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
  • Severity (CVSSv4.0): 6.1 (high)

Description:

The vulnerability was identified in ASUSTOR Data Master (ADM) versions 3.5.9.RUE3 and below, 4.0.5.RVI1 and below, 4.1.0.RJD1 and below.

The discovered vulnerability allows remote authenticated users to execute arbitrary code through the WebDAV protocol in susceptible versions of ASUSTOR Data Master (ADM).

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 29.08.2022

Recommendations:

  • ADM 3.5 - update to version 3.5.9.RWM1 or higher
  • ADM 4.0 - update to version 4.0.5.RWM1 or higher
  • ADM 4.1 - update to version 4.1.0.RKM1 or higher

Additional information: Security Bulletin

Researcher: Nikita Abramov (Positive Technologies)

Identifiers:

CVE-2022-37398

BDU:2022-05028

Vendor:

ASUSTOR

Vulnerable product:

ASUSTOR Data Master (ADM)

Vulnerable versions:

3.5.9.RUE3 and below, 4.0.5.RVI1 and below, 4.1.0.RJD1 and below