ASUSTOR ADM
cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*, +1 more
- >= 4.1.0, <= 4.3.3.RKD2
- >= 5.0.0, <= 5.1.0.RN42
A stack-based buffer overflow vulnerability has been identified in the VPN clients on Asustor's ADM operating system. This vulnerability arises from the use of unbounded input handling with sscanf(), combined with the direct output of user-controlled data to printf(). The absence of Position Independent Executable (PIE) and Stack Canary protections enables an authenticated remote attacker to exploit this flaw, executing arbitrary code as the web server user. The vulnerability affects Asustor ADM versions 4.1.0 prior to 4.3.3.RR42, as well as versions 5.0.0 prior to 5.1.2.REO1.
Exploitation of this vulnerability allows for stack-based buffer overflow, leading to arbitrary code execution on the affected system.
Users can upgrade to Asustor ADM 5.1.1.RCI1 or ADM 4.3.3.ROF1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.