| CVE ID | CVE-2023-27369 |
| CVSS SCORE | 8.8, AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| AFFECTED VENDORS |
NETGEAR |
| AFFECTED PRODUCTS |
RAX30 |
| VULNERABILITY DETAILS |
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the soap_serverd binary. When parsing the request headers, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to bypass authentication on the system. |
| ADDITIONAL DETAILS |
NETGEAR has issued an update to correct this vulnerability. More details can be found at:
https://kb.netgear.com/000065619/Security-Advisory-for-Multiple-Vulnerabilities-on-the-RAX30-PSV-2022-0348 |
| DISCLOSURE TIMELINE |
|
| CREDIT | Claroty Research - Vera Mens, Noam Moshe, Uri Katz, Sharon Brizinov |