CVE-2023-33635

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published May 31, 2023
Updated: Jan 10, 2025
CWE ID 787

Summary

CVE-2023-33635 is a newly identified vulnerability affecting the H3C Magic R300 router with software version R300-2100MV100R004. This issue involves a stack overflow that can be triggered through the UpdateMacClone interface, specifically at the /goform/aspForm endpoint. A successful exploitation could lead to crashing the affected component or potentially gaining unauthorized access to the system, posing a significant risk to network security. Organizations using this router model are advised to apply the necessary patches as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share