CVE-2024-32632
moderate-risk
Published 2024-04-16
A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access
Do I need to act?
-
0.17% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.6/10
Medium
ADJACENT_NETWORK
/ LOW complexity
Affected Products (13)
Asr1803Sc Firmware
Asr1607 Firmware
Asr3603 Firmware
Asr1806 Firmware
Asr1803 Firmware
Asr1606 Firmware
Asr1603 Firmware
Asr1602 Firmware
Asr1605 Firmware
Asr1609 Firmware
Asr3607 Firmware
Asr3605 Firmware
Asr3602 Firmware
Affected Vendors
References (2)
Vendor Advisory
https://www.asrmicro.com/en/goods/psirt?cid=38
Vendor Advisory
https://www.asrmicro.com/en/goods/psirt?cid=38
39
/ 100
moderate-risk
Severity
21/34 · High
Exploitability
1/34 · Minimal
Exposure
17/34 · Moderate