CVE-2023-2910: A Command injection vulnerability was found on Printer service of ADM
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2910?
CVE-2023-2910 is a vulnerability in the Printer service functionality in ASUSTOR Data Master (ADM) that allows remote unauthorized users to execute arbitrary commands.
What is the severity of CVE-2023-2910?
CVE-2023-2910 has a severity rating of 8.8 (High).
How does CVE-2023-2910 affect ASUSTOR Data Master?
CVE-2023-2910 affects ASUSTOR Data Master versions between 4.0.0.rib4 and 4.0.6.ris1, as well as versions between 4.1.0.rhu2 and 4.2.3.rk91.
How can I fix CVE-2023-2910?
To fix CVE-2023-2910, it is recommended to apply the latest security patch provided by ASUSTOR.
Where can I find more information about CVE-2023-2910?
You can find more information about CVE-2023-2910 in the security advisory on the ASUSTOR website.