CVE-2023-3697: A Command injection vulnerability was found on Printer service of ADM
Published Aug 17, 2023
·Updated
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.
Affected Software
2 affected components
ASUSTOR Data Master>=4.0.0.rib4<=4.0.6.ris1
ASUSTOR Data Master>=4.1.0.rhu2<4.2.3.rk91
Event History
Aug 17, 2023
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this printer service vulnerability?
The vulnerability ID for this printer service vulnerability is CVE-2023-3697.
2
What is the severity of CVE-2023-3697?
CVE-2023-3697 has a severity score of 8.5, classified as high.
3
Which software versions are affected by CVE-2023-3697?
The affected software versions include ADM 4.0.6.RIS1 and below, as well as ADM 4.1.0 and below, and ADM 4.2.2.RI61 and below.
4
How does CVE-2023-3697 impact the printer service?
CVE-2023-3697 allows remote unauthorized users to navigate beyond the intended directory structure and create files.
5
Is there any fix available for CVE-2023-3697?
Please refer to the official security advisory link provided for information on available fixes.