Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-26602


ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.


Published

2023-02-26T20:15:10.697

Last Modified

2024-11-21T07:51:50.250

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System asus asmb8-ikvm_firmware ≤ 1.14.51 Yes

References