Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 11 min 116 bronnen 1 kritiek 3 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2024-57480

CRITICAL · 9.8 CVSS Gepubliceerd: CWE-120

Beschrijving NL

H3C N12 V100R005 bevat een kwetsbaarheid voor bufferoverloop vanwege het ontbreken van lengteverificatie in de AP-configuratiefunctie. Aanvallers die dit beveiligingslek met succes misbruiken, kunnen ervoor zorgen dat het externe doelapparaat crasht of willekeurige opdrachten uitvoert door een POST-VERZOEK naar /bin/webs te sturen.

Origineel (Engels) tonen

H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.

Vendors

H3c

Affected products

N12 Firmware N12

References