CAYIN Technology CMS - OS Command Injection
Published Aug 14, 2024
7.2
HIGHCVSS 3.1
EPSS 0.72%
Description
The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and execute them on the remote server.
Affected products
-
- Version 11.0StatusaffectedConstraints-
- Version
-
- Version 11.0StatusaffectedConstraints-
- Version
-
- Version 11.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| CAYIN Technology | Cms-SE | unaffected |
| ||||||
| CAYIN Technology | Cms-Se(18.04) | unaffected |
| ||||||
| CAYIN Technology | Cms-Se(22.04) | unaffected |
|
No data.
-
- Version 11.0StatusaffectedConstraints-
- Version
-
- Version 11.0StatusaffectedConstraints-
- Version
-
- Version 11.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Cayintech | Cms-SE | n/a |
| ||||||
| Cayintech | Cms-Se\(18.04\) | n/a |
| ||||||
| Cayintech | Cms-Se\(22.04\) | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
For CMS-SE(22.04) v11.0, install patch P23005 or later. For CMS-SE(18.04) v11.0, install patch P23006 or later. For CMS-SE v11.0, Install patch P23007 or later.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48605 Advisory
- https://resource1.cayintech.com/patch/ patch
- https://www.twcert.org.tw/en/cp-139-8002-b6167-2.html third-party-advisory
- https://www.twcert.org.tw/tw/cp-132-8001-8416d-1.html third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48605 | Advisory | |
| https://resource1.cayintech.com/patch/ | patch | |
| https://www.twcert.org.tw/en/cp-139-8002-b6167-2.html | third-party-advisory | |
| https://www.twcert.org.tw/tw/cp-132-8001-8416d-1.html | third-party-advisory |
Change history (0)
No recorded changes yet.