Record summary

CVE-2024-5421 has a selected CVSS score of 8.7 (high); EIP currently links 1 Nuclei template.

Description

Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2024 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 20.1.22affected

Default status: unaffected

CVE ListThrough 20.1.22affected

Default status: unaffected

CVE ListThrough 20.1.22affected

Default status: unknown

CVE ListThrough 20.1.22affected

Default status: unknown

CVE ListThrough 20.1.22affected

Default status: unknown

CVE ListThrough 20.1.22affected

Nuclei templates

1
ProjectDiscoveryHIGHSEH utnserver Pro/ProMAX/INU-100 20.1.22 - File ExposureCVSS 8.7

A vulnerability was identified in utnserver Pro, utnserver ProMAX, and INU-100 version 20.1.22 and earlier, impacting the file handling functions. This flaw results in authenticated file disclosure, granting unauthorized access to sensitive files and directories. Although authentication is required, the vulnerability poses a significant risk of data exposure. This vulnerability is publicly disclosed and identified as CVE-2024-5421.

Impact

Authenticated attackers can access arbitrary files and directories on the system, potentially exposing sensitive configuration files, credentials, and system information.

Remediation

Update SEH utnserver Pro/ProMAX/INU-100 to a version later than 20.1.22 that addresses the path traversal vulnerability.

WeaknessesCWE-78
Authorsbl4ckp4r4d1s3
Template tagscvecve2024utnserversehexposurevuln
CVSS vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L
Shodan: SEH HTTP Server

Source: ProjectDiscovery

References

3