PT-2024-17358 · Ixsystems · Ixsystems Truenas Core

Daan Keuper

+2

·

Published

2024-12-06

·

Updated

2025-08-18

·

CVE-2024-11946

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions iXsystems TrueNAS CORE (affected versions not specified)
Description This issue allows network-adjacent attackers to tamper with firmware update files on affected installations of iXsystems TrueNAS devices. The specific flaw exists within the handling of firmware updates, resulting from the use of an insecure protocol to deliver updates. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. No authentication is required to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-11946
ZDI-24-1644

Affected Products

Ixsystems Truenas Core