CVE-2023-2509
Estado: ModificadaMedia (6.1)—
A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this vulnerability to inject malicious scripts into the target applications to access any cookies or sensitive information retained by the browser and used with that application. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below, LooksGood 2.0.0.R129 and below and SoundsGood 2.3.0.r1027 and below.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.34%
- Percentil entre todas las CVEs puntuadas: 25
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-79
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-2509",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-2509",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-01-22T16:51:21.778917Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@asustor.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.5,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@asustor.com",
"affectedData": [
{
"vendor": "ASUSTOR",
"product": "ADM",
"versions": [
{
"status": "affected",
"version": "4.0",
"versionType": "custom",
"lessThanOrEqual": "4.0.6.REG2"
},
{
"status": "affected",
"version": "4.1",
"versionType": "custom",
"lessThanOrEqual": "4.1.0.RLQ1"
},
{
"status": "affected",
"version": "4.2",
"versionType": "custom",
"lessThanOrEqual": "4.2.1.RGE2"
}
],
"platforms": [
"Linux",
"x86",
"64 bit",
"ARM"
],
"packageName": "Web Center",
"defaultStatus": "unaffected"
},
{
"vendor": "ASUSTOR",
"product": "LooksGood",
"versions": [
{
"status": "affected",
"version": "2.0",
"versionType": "custom",
"lessThanOrEqual": "2.0.0.R129"
}
],
"platforms": [
"Linux",
"x86",
"ARM",
"64 bit"
],
"defaultStatus": "unaffected"
},
{
"vendor": "ASUSTOR",
"product": "SoundsGood",
"versions": [
{
"status": "affected",
"version": "2.3",
"versionType": "custom",
"lessThanOrEqual": "2.3.0.r1027"
}
],
"platforms": [
"Linux",
"x86",
"ARM",
"64 bit"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-05-17T07:15:08.567",
"references": [
{
"url": "https://www.asustor.com/security/security_advisory_detail?id=22",
"tags": [
"Vendor Advisory"
],
"source": "security@asustor.com"
},
{
"url": "https://www.asustor.com/security/security_advisory_detail?id=22",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@asustor.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this vulnerability to inject malicious scripts into the target applications to access any cookies or sensitive information retained by the browser and used with that application. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below, LooksGood 2.0.0.R129 and below and SoundsGood 2.3.0.r1027 and below."
}
],
"lastModified": "2026-06-17T05:52:45.007",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:asustor:adm:4.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E263E01C-BF3F-4107-989E-8EE195511DF7"
},
{
"criteria": "cpe:2.3:a:asustor:adm:4.0.6:reg2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD67EA77-03E9-435C-B1AF-C6EEEB69E55F"
},
{
"criteria": "cpe:2.3:a:asustor:adm:4.1.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0284FF36-321E-471E-A1E9-58A36E7A8039"
},
{
"criteria": "cpe:2.3:a:asustor:adm:4.1.0:rlq1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C6FBB975-F3A3-41C6-822A-AF32997422F6"
},
{
"criteria": "cpe:2.3:a:asustor:adm:4.2.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E95A07A-CA6B-4E79-BF1A-F1A3A97D1C9F"
},
{
"criteria": "cpe:2.3:a:asustor:adm:4.2.1:rge2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "62B4CDB5-AF06-40D1-A243-7577BAF3D001"
},
{
"criteria": "cpe:2.3:a:asustor:looksgood:2.0.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B03279A2-073F-463B-86FA-2BC862F94227"
},
{
"criteria": "cpe:2.3:a:asustor:looksgood:2.0.0:r129:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D64E2127-EB5B-450A-A4A0-0967CAC153C9"
},
{
"criteria": "cpe:2.3:a:asustor:soundsgood:2.3.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6311BD0B-3160-4C44-A837-414885F6EABF"
},
{
"criteria": "cpe:2.3:a:asustor:soundsgood:2.3.0:r1027:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0CE69E6-949C-4A8D-B54C-03398447D012"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@asustor.com"
}