CVE-2023-27805: Medium severity h3c magic r100 firmware vulnerability
H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-27805.
What software is affected by this vulnerability?
The H3C Magic R100 firmware version v100r005 is affected by this vulnerability.
What is the severity rating of CVE-2023-27805?
CVE-2023-27805 has a severity rating of 4.9 (medium).
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending a crafted payload through the EditSTList interface at /goform/aspForm, leading to a stack overflow and causing a Denial of Service (DoS) condition.
Is there a fix available for this vulnerability?
At the moment, there is no specific fix available for CVE-2023-27805. It is recommended to monitor the vendor's website for any security updates or patches.