CVE-2024-57473
Last modified
CVE-2024-57473 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address editing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address editing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| H3c | N12 Firmware | 100r005 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-57473?
How severe is CVE-2024-57473?
How do I fix CVE-2024-57473?
Are you affected by CVE-2024-57473?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
