CVE-2023-27810: Medium severity h3c magic r100 firmware vulnerability
Published Apr 7, 2023
·Updated
H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqoslanipeditlist interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
Affected Software
4 affected components
All of the following
H3C Magic R100 Firmware=v100r005
H3C Magic R100 Firmware
H3C Magic R100 Firmware=v100r005
H3C Magic R100 Firmware
Event History
Apr 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-27810?
CVE-2023-27810 is a vulnerability found in H3C Magic R100 R100V100R005.bin firmware that allows attackers to cause a Denial of Service (DoS) via a crafted payload.
2
How severe is CVE-2023-27810?
CVE-2023-27810 has a severity rating of 4.9 (medium).
3
Which software is affected by CVE-2023-27810?
H3C Magic R100 firmware v100r005 is affected by CVE-2023-27810.
4
How can CVE-2023-27810 be exploited?
CVE-2023-27810 can be exploited by attackers through the ipqos_lanip_editlist interface at /goform/aspForm.
5
Is there a fix for CVE-2023-27810?
Yes, it is recommended to update the H3C Magic R100 firmware to a version that is not vulnerable to CVE-2023-27810.