Record summary

CVE-2024-46627 has a selected CVSS score of 9.1 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 27, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List2.2affected

Proofs of concept

1

Repository PoCs

GitHubd4lyw/CVE-2024-46627Repository PoCby d4lywStars: 0Not analyzed1 file

1.1 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALDATAGERRY - REST API Auth BypassCVSS 9.1

Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.

Impact

Allows unauthorized access to REST API

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

WeaknessesCWE-284
Authorsgy741
Template tagscvecve2024becondatagerryunauthauth-bypassvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Shodan: http.title:"datagerry"

Source: ProjectDiscovery

References

5