gist.github.com
https://gist.github.com/LemonSec/6aaea8320187a38e1a398fa321f12303 CVE-2024-38944
CRITICAL
Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
Record summary
CVE-2024-38944 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 23, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
x_1l_traffic_controller_maxtimeBrowse intelight / x_1l_traffic_controller_maxtimeDefault status: unknown | CVE List | v1.9.6 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBIntelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)ExploitDB exploitby Andrew Lemon/Red ThreatNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-38944