{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T16:29:53.399","vulnerabilities":[{"cve":{"id":"CVE-2022-37398","sourceIdentifier":"security@asustor.com","published":"2022-08-05T17:15:08.997","lastModified":"2026-06-17T04:55:01.820","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected ADM versions include: 3.5.9.RUE3 and below, 4.0.5.RVI1 and below as well as 4.1.0.RJD1 and below."},{"lang":"es","value":"Se ha encontrado una vulnerabilidad de desbordamiento de búfer en la región stack de la memoria dentro de ADM cuando usa WebDAV debido a una falta de validación del tamaño de los datos. Un atacante puede explotar esta vulnerabilidad para ejecutar código arbitrario. Las versiones de ADM afectadas son: 3.5.9.RUE3 y anteriores, 4.0.5.RVI1 y anteriores, así como 4.1.0.RJD1 y anteriores"}],"affected":[{"source":"security@asustor.com","affectedData":[{"vendor":"ASUSTOR","product":"ADM","versions":[{"version":"3.5","lessThanOrEqual":"3.5.9.RUE3","versionType":"custom","status":"affected"},{"version":"4.0","lessThanOrEqual":"4.0.5.RVI1","versionType":"custom","status":"affected"},{"version":"4.1","lessThanOrEqual":"4.1.0.RJD1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@asustor.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-02T14:35:46.295884Z","id":"CVE-2022-37398","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@asustor.com","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5.0","versionEndIncluding":"3.5.9.rue3","matchCriteriaId":"792CC2E3-7FC2-428E-AA55-92D093D97DB4"},{"vulnerable":true,"criteria":"cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndIncluding":"4.0.5.rvi1","matchCriteriaId":"6521DF3B-B73C-4345-BE19-1C7F8B9E283C"},{"vulnerable":true,"criteria":"cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1.0","versionEndIncluding":"4.1.0.rjd1","matchCriteriaId":"6CD1D147-FB0B-4A4D-A483-FCD74D47DB27"}]}]}],"references":[{"url":"https://www.asustor.com/security/security_advisory_detail?id=12","source":"security@asustor.com","tags":["Vendor Advisory"]},{"url":"https://www.asustor.com/security/security_advisory_detail?id=12","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}