PoC Index

CVE-2019-11688

HIGH 8.8EPSS 1.1%

An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any certificate for asustornasapi.asustor.com. In other words, there is Missing SSL Certificate Validation.

CVSS v3.1
7.4 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v2.0
8.8 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:N
EPSS
1.10% chance of exploitation in the next 30 days, 63th percentile
Published
2020-03-18
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related