Remote Attackers Can Execute Arbitrary Code via SNMP in ASUS Firmware
CVE-2023-26602
9.8CRITICAL
Key Information
- Vendor
- Asus
- Status
- Asmb8-ikvm Firmware
- Vendor
- CVE Published:
- 26 February 2023
Badges
πΎ Exploit Existsπ£ EPSS 48%
Summary
ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.
References
EPSS Score
48% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database0 Proof of Concept(s)