CVE-2023-2909

HIGH

ASUSTOR ADM < 4.0.6.REG2, 4.1.0, 4.2.1.RGE2 - Path Traversal and Arbitrary File Deletion via EZ Sync Service

Title source: llm
STIX 2.1

Description

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.

References (1)

Core 1
Core References

Scores

CVSS v3 8.5
EPSS 0.0067
EPSS Percentile 47.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
asustor/adm 4.0.0 - 4.0.6.reg2
Published May 31, 2023
Tracked Since Feb 18, 2026