CVE-2024-31843

MEDIUM

Italtel Embrace <1.6.4 - Command Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allows authenticated users to execute commands on the Operating System.

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://www.gruppotim.it/it/footer/red-team.html

Scores

CVSS v3 4.1
EPSS 0.0054
EPSS Percentile 40.9%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
italtel/embrace 1.6.4
Published May 23, 2024
Tracked Since Feb 18, 2026