CVE-2024-0401
published 2024-05-20CVE-2024-0401: ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary…
PriorityP347high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.73%
50.1th percentile
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| asus | expertwifi | < 3.0.0.6.102_44544 | 3.0.0.6.102_44544 |
| asus | rt-ac67u | < 3.0.0.4.386_51685 | 3.0.0.4.386_51685 |
| asus | rt-ac68r | < 3.0.0.4.386_51685 | 3.0.0.4.386_51685 |
| asus | rt-ac68u | < 3.0.0.4.386_51685 | 3.0.0.4.386_51685 |
| asus | rt-ac86u | < 3.0.0.4.386_51925 | 3.0.0.4.386_51925 |
| asus | rt-ax3000 | < 3.0.0.4.388_24762 | 3.0.0.4.388_24762 |
| asus | rt-ax55 | < 3.0.0.4.386_52303 | 3.0.0.4.386_52303 |
| asus | rt-ax58u | < 3.0.0.4.388_24762 | 3.0.0.4.388_24762 |
| asus | rt-ax86_series | < 3.0.0.4.388_24243 | 3.0.0.4.388_24243 |
| asus | rt-ax88u | < 3.0.0.4.388_24209 | 3.0.0.4.388_24209 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qxjr-363m-qwfv: ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability
ghsa_unreviewed·2024-05-20
CVE-2024-0401 [HIGH] CWE-78 GHSA-qxjr-363m-qwfv: ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.
Oracle
Oracle Oracle Analytics Risk Matrix: Installation, BI Platform Security (OpenSSL) — CVE-2023-0401
vendor_oracle·2024-10-15·CVSS 7.5
CVE-2023-0401 [HIGH] Oracle Oracle Analytics Risk Matrix: Installation, BI Platform Security (OpenSSL) — CVE-2023-0401
Oracle Oracle Analytics Risk Matrix: Installation, BI Platform Security (OpenSSL) vulnerability
CVE: CVE-2023-0401
CVSS: 7.5
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-20
Published