CVE-2024-5421
Authenticated Command Injection
Record summary
CVE-2024-5421 has a selected CVSS score of 8.7 (high); EIP currently links 1 Nuclei template.
Description
Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2024 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through 20.1.22 | affected |
utnserver ProBrowse SEH Computertechnik / utnserver ProDefault status: unaffected | CVE List | Through 20.1.22 | affected |
utnserver ProMAXBrowse SEH Computertechnik / utnserver ProMAXDefault status: unaffected | CVE List | Through 20.1.22 | affected |
inu-100Browse seh / inu-100Default status: unknown | CVE List | Through 20.1.22 | affected |
utnserver_proBrowse seh / utnserver_proDefault status: unknown | CVE List | Through 20.1.22 | affected |
utnserver_promaxBrowse seh / utnserver_promaxDefault status: unknown | CVE List | Through 20.1.22 | affected |
Nuclei templates
1ProjectDiscoveryHIGHSEH utnserver Pro/ProMAX/INU-100 20.1.22 - File ExposureCVSS 8.7
A vulnerability was identified in utnserver Pro, utnserver ProMAX, and INU-100 version 20.1.22 and earlier, impacting the file handling functions. This flaw results in authenticated file disclosure, granting unauthorized access to sensitive files and directories. Although authentication is required, the vulnerability poses a significant risk of data exposure. This vulnerability is publicly disclosed and identified as CVE-2024-5421.
Impact
Authenticated attackers can access arbitrary files and directories on the system, potentially exposing sensitive configuration files, credentials, and system information.
Remediation
Update SEH utnserver Pro/ProMAX/INU-100 to a version later than 20.1.22 that addresses the path traversal vulnerability.
Source: ProjectDiscovery