CVE-2023-33641
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published May 31, 2023
Updated: Jan 10, 2025
CWE ID 787
Summary
CVE-2023-33641 is a recently disclosed vulnerability affecting the H3C Magic R300 router running software version R300-2100MV100R004. This issue involves a stack overflow vulnerability located within the AddMacList interface, specifically at the /goform/aspForm endpoint. Successful exploitation of this weakness could lead to denial of service or potentially more serious attacks on the affected system. It is recommended that users of this device upgrade to a newer, secure version of firmware as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- New H3C Technologies Co. Ltd.