CVE-2023-27802: Medium severity h3c magic r100 firmware vulnerability
Published Apr 7, 2023
·Updated
H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditvsList parameter at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
Affected Software
4 affected components
H3C Magic R100 Firmware=v100r005
H3C Magic R100 Firmware
All of the following
H3C Magic R100 Firmware=v100r005
H3C Magic R100 Firmware
Event History
Apr 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-27802?
CVE-2023-27802 is a vulnerability discovered in H3C Magic R100 firmware v100r005, which allows attackers to cause a Denial of Service (DoS) through a stack overflow via the EditvsList parameter.
2
How severe is CVE-2023-27802?
CVE-2023-27802 has a severity value of 4.9, which is considered medium.
3
What is affected by CVE-2023-27802?
The H3C Magic R100 firmware version v100r005 is affected by CVE-2023-27802.
4
How can CVE-2023-27802 be exploited?
CVE-2023-27802 can be exploited by sending a crafted payload to the EditvsList parameter at /goform/aspForm.
5
Is there a fix available for CVE-2023-27802?
At the moment, there is no information available regarding a fix for CVE-2023-27802.