ASUS Armoury Crate - Arbitrary File Write
CVE-2023-5716
9.8CRITICAL
Summary
ASUS Armoury Crate is susceptible to an arbitrary file write vulnerability that permits remote attackers to upload or modify files on affected systems without adequate permissions. This vulnerability can be exploited by sending specially crafted HTTP requests, leading to unauthorized access to sensitive files. The potential impact of this vulnerability underscores the necessity for users to monitor their systems for exploitation attempts and apply recommended security updates promptly.
Affected Version(s)
Armoury Crate V4.0.1.3
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved