CVE Database
/

CVE-2022-37398

Back to search

CVE-2022-37398

Published: Aug 5, 2022

Modified: Jun 2, 2026

PUBLISHED

CVSS v3.1

7.1

HIGH

Description

A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected ADM versions include: 3.5.9.RUE3 and below, 4.0.5.RVI1 and below as well as 4.1.0.RJD1 and below.

VendorProductVersions

ASUSTOR

ADM

affected
3.5 - <= 3.5.9.RUE3
affected
4.0 - <= 4.0.5.RVI1
affected
4.1 - <= 4.1.0.RJD1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now