Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability
Published Aug 21, 2024
8.0
HIGHCVSS 3.1
EPSS 1.71%
Description
Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Magnet Forensics AXIOM. User interaction is required to exploit this vulnerability in that the target must acquire data from a malicious mobile device.
The specific flaw exists within the Android device image acquisition functionality. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-23964.
Affected products
-
- Version 8.0.0.39753StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Magnet Forensics | Axiom | n/a |
|
- 8.0.0.39753
-
- Version 8.0.0.39753StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Magnet Forensics | Axiom | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://docs.magnetforensics.com/docs/axiom/release_notes.html vendor-advisoryRelease Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48370 Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-24-1129/ x_research-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://docs.magnetforensics.com/docs/axiom/release_notes.html | vendor-advisoryRelease Notes | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48370 | Advisory | |
| https://www.zerodayinitiative.com/advisories/ZDI-24-1129/ | x_research-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.