Denial of Service Vulnerability in H3C Magic R100 by H3C
CVE-2023-27805

4.9MEDIUM

Key Information:

Vendor
H3c
Vendor
CVE Published:
7 April 2023

Summary

The H3C Magic R100 device contains a stack overflow vulnerability in the EditSTList interface located at /goform/aspForm. This vulnerability can be exploited by attackers using specially crafted payloads, leading to potential Denial of Service (DoS) conditions. This presents significant risks to device availability and network integrity.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.