CVE-2023-33635
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2023-33635 is a newly identified vulnerability affecting the H3C Magic R300 router with software version R300-2100MV100R004. This issue involves a stack overflow that can be triggered through the UpdateMacClone interface, specifically at the /goform/aspForm endpoint. A successful exploitation could lead to crashing the affected component or potentially gaining unauthorized access to the system, posing a significant risk to network security. Organizations using this router model are advised to apply the necessary patches as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- New H3C Technologies Co. Ltd.