CVE-2023-30770 HIGH

CVE-2023-30770: A stack-based buffer overflow vulnerability was found in the ADM

Vendor Asustor
Product ADM
Weakness CWE-787
Published April 17, 2023
Last update February 5, 2025

CVSS base score

7.1/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H

What the vulnerability does

01Description

A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can exploit this vulnerability to execute arbitrary code. Affected ADM versions include: 4.0.6.REG2, 4.1.0 and below as well as 4.2.0.RE71 and below.

Key dates

02Disclosure timeline

April 17, 2023 CVE published
February 5, 2025 Record updated