CVE-2023-26602 Information
Mar 01, 2023
cve
Description
ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.
Reference
https://nwsec.de/NWSSA-002-2023.txt http://packetstormsecurity.com/files/171137/ASUS-ASMB8-iKVM-1.14.51-SNMP-Remote-Root.html http://seclists.org/fulldisclosure/2023/Feb/15
Share on: