Vulnerability Name: | CVE-2021-41437 (CCN-237369) | ||||||||||||
Assigned: | 2021-09-20 | ||||||||||||
Published: | 2022-09-24 | ||||||||||||
Updated: | 2022-09-27 | ||||||||||||
Summary: | An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker. | ||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-436 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-41437 Source: XF Type: UNKNOWN asus-cve202141437-info-disc(237369) Source: CCN Type: GitHub Web site HTTP Response splitting (CVE-2021-41437) Source: MISC Type: Patch, Third Party Advisory https://github.com/efchatz/easy-exploits/tree/main/Web/ASUS/CVE-2021-41437 Source: CCN Type: ASUS Web site RT-AX88U Source: CONFIRM Type: Patch, Product, Vendor Advisory https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AX88U/HelpDesk_BIOS/ | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |