Description
ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service.
No analysis available yet.
Remediation
Vendor Solution
Update the version to 3.0.0.4_388_23748 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-45852 | ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7371-aecf1-1.html |
|
History
Wed, 25 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-25T15:39:19.468Z
Reserved: 2023-08-29T00:11:47.812Z
Link: CVE-2023-41349
Updated: 2024-08-02T19:01:34.257Z
Status : Modified
Published: 2023-09-18T03:15:08.113
Modified: 2024-11-21T08:21:07.613
Link: CVE-2023-41349
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD