CVE-2024-57480
Beschrijving NL
H3C N12 V100R005 bevat een kwetsbaarheid voor bufferoverloop vanwege het ontbreken van lengteverificatie in de AP-configuratiefunctie. Aanvallers die dit beveiligingslek met succes misbruiken, kunnen ervoor zorgen dat het externe doelapparaat crasht of willekeurige opdrachten uitvoert door een POST-VERZOEK naar /bin/webs te sturen.
Origineel (Engels) tonen
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.