CVE-2022-37398

HIGH

ASUSTOR ADM < 3.5.9.rue3, <= 4.0.5.RVI1, <= 4.1.0.RJD1 - Stack-based Buffer Overflow via WebDAV

Title source: llm
STIX 2.1

Description

A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected ADM versions include: 3.5.9.RUE3 and below, 4.0.5.RVI1 and below as well as 4.1.0.RJD1 and below.

References (1)

Core 1
Core References

Scores

CVSS v3 7.1
EPSS 0.0059
EPSS Percentile 44.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-121 CWE-787
Status published
Products (4)
ASUSTOR/ADM 3.5 - 3.5.9.RUE3
asustor/adm 3.5.0 - 3.5.9.rue3
ASUSTOR/ADM 4.0 - 4.0.5.RVI1
ASUSTOR/ADM 4.1 - 4.1.0.RJD1
Published Aug 05, 2022
Tracked Since Feb 18, 2026