CVE-2023-2909
31.05.2023, 10:15
EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.
Vendor | Product | Version |
---|---|---|
asustor | adm | 4.0.0 ≤ 𝑥 ≤ 4.0.6.reg2 |
asustor | adm | 4.1.0 ≤ 𝑥 ≤ 4.1.0rlq1 |
asustor | adm | 4.2.0 ≤ 𝑥 ≤ 4.2.1.rge2 |
𝑥
= Vulnerable software versions