Stack Overflow Vulnerability in H3C Magic R100 Devices
CVE-2023-27803
4.9MEDIUM
Summary
A stack overflow vulnerability was identified in the H3C Magic R100 device, specifically through the EdittriggerList interface at /goform/aspForm. This flaw permits attackers to execute a Denial of Service (DoS) attack by sending a specially crafted payload to the affected device, potentially disrupting its service and operation. Organizations using this device must take precautions to mitigate the risk associated with this vulnerability and apply any relevant patches provided by the vendor.
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved