CRITICAL

CVE-2023-26602

CVSS v3

9.8

CRITICAL

EPSS Score

75.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.

Technical details

Published
2/26/2023
Exploit-DB
EDB-52244

Frequently asked questions

What is CVE-2023-26602?

ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.

Is CVE-2023-26602 actively exploited?

Active exploitation of CVE-2023-26602 has not been confirmed. The EPSS score is 75.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-26602?

CVE-2023-26602 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-26602 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.