CVE-2023-3699: An Improper Privilege Management vulnerability was found on the ADM
An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-3699.
What is the title of this vulnerability?
The title of this vulnerability is 'An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration.'
What is the severity of CVE-2023-3699?
The severity of CVE-2023-3699 is high, with a severity value of 5.5.
How does CVE-2023-3699 affect ASUSTOR Data Master (ADM)?
CVE-2023-3699 affects ASUSTOR Data Master (ADM) versions 4.0.6.RIS1, 4.1.0 and below, as well as 4.2.2.RI61 and below.
Is there a fix available for CVE-2023-3699?
To fix CVE-2023-3699, it is recommended to update ASUSTOR Data Master (ADM) to version 4.2.3.RK91 or later.