Stack Overflow Vulnerability in H3C Magic R100 Devices
CVE-2022-30914

9.8CRITICAL

Key Information:

Vendor
H3c
Vendor
CVE Published:
8 June 2022

Summary

The H3C Magic R100 devices were found to have a stack overflow vulnerability that can be exploited through the UpdateMacClone parameter within the /goform/aspForm endpoint. This vulnerability allows attackers to execute unauthorized actions on the device, potentially leading to a compromise of the system's integrity and confidentiality. Users of the affected version, R100V100R005, should take immediate action to assess and mitigate risks associated with this security issue.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.