daly.wtf
https://daly.wtf/cve-2024-46627-incorrect-access-control-in-becn-datagerry-v2-2-allows-attackers-to-execute-arbitrary-commands-via-crafted-web-requests CVE-2024-46627
CRITICALNuclei
DATAGERRY - REST API Auth Bypass
Record summary
CVE-2024-46627 has a selected CVSS score of 9.1 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
datagerryBrowse becn / datagerryDefault status: unknown | CVE List | 2.2 | affected |
Proofs of concept
1Repository PoCs
GitHubd4lyw/CVE-2024-46627Repository PoCby d4lywStars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALDATAGERRY - REST API Auth BypassCVSS 9.1
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
Impact
Allows unauthorized access to REST API
Remediation
Apply the latest security patches and updates from the vendor to address this vulnerability.
WeaknessesCWE-284
Authorsgy741
Template tagscvecve2024becondatagerryunauthauth-bypassvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Shodan: http.title:"datagerry"
https://nvd.nist.gov/vuln/detail/CVE-2024-46627 https://daly.wtf/cve-2024-46627-incorrect-access-control-in-becn-datagerry-v2-2-allows-attackers-to-execute-arbitrary-commands-via-crafted-web-requests/ https://datagerry.com/ https://github.com/DATAGerry/ https://github.com/d4lyw/CVE-2024-46627
Source: ProjectDiscovery
References
5datagerry.com
https://datagerry.com/ github.com
https://github.com/DATAGerry github.com
https://github.com/d4lyw/CVE-2024-46627 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-46627