PT-2024-22870 · Addactis · Addactis Ibnrs

Ismailcemunver

·

Published

2024-04-04

·

Updated

2024-04-04

·

CVE-2024-29375

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Addactis IBNRS version 3.10.3.107
Description The issue allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles), and Yield Curve Name parameters.
Recommendations For Addactis IBNRS version 3.10.3.107, consider restricting access to the parameters Project Description, Identifiers, Custom Triangle Name, and Yield Curve Name to minimize the risk of exploitation. Avoid using crafted .ibnrs files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-29375

Affected Products

Addactis Ibnrs