VulnerabilityModified
CVE-2012-4924
Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execute arbitrary code via a long parameter to the Alert method.
HIGH 9.3EPSS 36.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 36.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execute arbitrary code via a long parameter to the Alert method.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 36.34% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- asus/ipswcom activex component · asus/net4switch
- Source
- cve@mitre.org
References
- http://dsecrg.com/pages/vul/show.php?id=417
- http://osvdb.org/79438
- http://secunia.com/advisories/48125Vendor Advisory
- http://www.exploit-db.com/exploits/18538Exploit
- http://www.securityfocus.com/bid/52110
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73384
- http://dsecrg.com/pages/vul/show.php?id=417
- http://osvdb.org/79438
- http://secunia.com/advisories/48125Vendor Advisory
- http://www.exploit-db.com/exploits/18538Exploit
- http://www.securityfocus.com/bid/52110
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73384
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.