mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-07-30 18:04:30 +00:00
352 lines
16 KiB
JSON
352 lines
16 KiB
JSON
{
|
|
"data_version": "4.0",
|
|
"data_type": "CVE",
|
|
"data_format": "MITRE",
|
|
"CVE_data_meta": {
|
|
"ID": "CVE-2024-3912",
|
|
"ASSIGNER": "cve@cert.org.tw",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device."
|
|
}
|
|
]
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "CWE-434 Unrestricted Upload of File with Dangerous Type",
|
|
"cweId": "CWE-434"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "ASUS",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "DSL-N17U",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_792"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N55U_C1",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_792"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N55U_D1",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_792"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N66U",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_792"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N12U_C1",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_807"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N12U_D1",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_807"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N14U",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_807"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N14U_B1",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_807"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N16",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_999"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-AC51",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_999"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-AC750",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_999"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-AC52U",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_999"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-AC55U",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_999"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-AC56U",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "earlier",
|
|
"version_value": "1.1.2.3_999"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N10_C1",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N10_D1",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N10P_C1",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N12E_C1",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N16P",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-N16U",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-AC52",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "DSL-AC55",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "All"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"url": "https://www.twcert.org.tw/tw/cp-132-7875-872d3-1.html",
|
|
"refsource": "MISC",
|
|
"name": "https://www.twcert.org.tw/tw/cp-132-7875-872d3-1.html"
|
|
},
|
|
{
|
|
"url": "https://www.twcert.org.tw/en/cp-139-7876-396bd-2.html",
|
|
"refsource": "MISC",
|
|
"name": "https://www.twcert.org.tw/en/cp-139-7876-396bd-2.html"
|
|
}
|
|
]
|
|
},
|
|
"generator": {
|
|
"engine": "Vulnogram 0.2.0"
|
|
},
|
|
"source": {
|
|
"advisory": "TVN-202406011",
|
|
"discovery": "EXTERNAL"
|
|
},
|
|
"solution": [
|
|
{
|
|
"lang": "en",
|
|
"supportingMedia": [
|
|
{
|
|
"base64": false,
|
|
"type": "text/html",
|
|
"value": "Update following models to version 1.1.2.3_792 or later\uff1a<br>DSL-N17U, DSL-N55U_C1, DSL-N55U_D1, DSL-N66U<br><br>Update following models to version 1.1.2.3_807 or later\uff1a<br>DSL-N12U_C1, DSL-N12U_D1, DSL-N14U, DSL-N14U_B1<br><br>Update following models to version 1.1.2.3_999 or later\uff1a<br>DSL-N16, DSL-AC51, DSL-AC750, DSL-AC52U, DSL-AC55U, DSL-AC56U<br><br>The following models are no longer maintained, and it is recommended to retire and replace them.<br>DSL-N10_C1, DSL-N10_D1, DSL-N10P_C1, DSL-N12E_C1, ,DSL-N16P, DSL-N16U, DSL-AC52, DSL-AC55<br>\n\n<span style=\"background-color: rgb(255, 255, 255);\">If replacement is not possible in the short term, it is recommended to disable remote access (Web access from WAN), virtual servers (Port forwarding), DDNS, VPN server, DMZ, and port trigger.</span>\n\n<br>"
|
|
}
|
|
],
|
|
"value": "Update following models to version 1.1.2.3_792 or later\uff1a\nDSL-N17U, DSL-N55U_C1, DSL-N55U_D1, DSL-N66U\n\nUpdate following models to version 1.1.2.3_807 or later\uff1a\nDSL-N12U_C1, DSL-N12U_D1, DSL-N14U, DSL-N14U_B1\n\nUpdate following models to version 1.1.2.3_999 or later\uff1a\nDSL-N16, DSL-AC51, DSL-AC750, DSL-AC52U, DSL-AC55U, DSL-AC56U\n\nThe following models are no longer maintained, and it is recommended to retire and replace them.\nDSL-N10_C1, DSL-N10_D1, DSL-N10P_C1, DSL-N12E_C1, ,DSL-N16P, DSL-N16U, DSL-AC52, DSL-AC55\n\n\nIf replacement is not possible in the short term, it is recommended to disable remote access (Web access from WAN), virtual servers (Port forwarding), DDNS, VPN server, DMZ, and port trigger."
|
|
}
|
|
],
|
|
"impact": {
|
|
"cvss": [
|
|
{
|
|
"attackComplexity": "LOW",
|
|
"attackVector": "NETWORK",
|
|
"availabilityImpact": "HIGH",
|
|
"baseScore": 9.8,
|
|
"baseSeverity": "CRITICAL",
|
|
"confidentialityImpact": "HIGH",
|
|
"integrityImpact": "HIGH",
|
|
"privilegesRequired": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"userInteraction": "NONE",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
|
"version": "3.1"
|
|
}
|
|
]
|
|
}
|
|
} |