CVE-2024-31161
Last modified
CVE-2024-31161 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be executed upon browsing the webpage.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Asus | Download Master | < 3.1.0.114 |
References
- https://www.twcert.org.tw/en/cp-139-7866-469e0-2.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7865-d3823-1.htmlThird Party Advisory
- https://www.twcert.org.tw/en/cp-139-7866-469e0-2.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7865-d3823-1.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-31161?
How severe is CVE-2024-31161?
How do I fix CVE-2024-31161?
Are you affected by CVE-2024-31161?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
