CVE-2023-5716

CRITICAL

Asus Armoury Crate < 4.1.0.8 - Missing Authentication

Title source: rule

Description

ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission.

Scores

CVSS v3 9.8
EPSS 0.0089
EPSS Percentile 75.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-306
Status published

Affected Products (1)

asus/armoury_crate < 4.1.0.8

Timeline

Published Jan 19, 2024
Tracked Since Feb 18, 2026