Impact
A format string flaw exists in the Notification OAuth settings of ADM because user‑controlled notification configuration input is processed by an unsafe format string routine. The vulnerability is classified as CWE‑134. An authenticated administrator can leverage the flaw to leak sensitive memory contents or to cause the affected component to crash, resulting in a denial of service. The attack vector is likely an internal one, requiring administrative privileges to modify notification settings.
Affected Systems
ASUSTOR Inc. ADM versions 4.1.0 through 4.3.3.RUN1 and 5.0.0 through 5.1.3.RI81 are affected.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of < 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. Since exploitation requires an authenticated administrator, the risk remains significant if privileged accounts are compromised or misused. Prompt remediation is warranted to prevent potential data leakage or service disruption.
OpenCVE Enrichment