CVE-2023-33632
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published May 31, 2023
Updated: Jan 10, 2025
CWE ID 787
Summary
CVE-2023-33632 is a newly discovered stack overflow vulnerability affecting the H3C Magic R300 router, specifically versions prior to R300-2100MV100R004. This issue can be exploited through the ipqos_lanip_dellist interface located at /goform/aspForm. Successful exploitation could lead to a denial-of-service condition or even remote code execution, posing a significant risk to affected networks. It is recommended that users upgrade to the latest, patched version of their H3C Magic R300 firmware to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- New H3C Technologies Co. Ltd.