PT-2024-24148 · Beijing Panabit Network Software Co. · Analog

Published

2024-04-26

·

Updated

2024-08-01

·

CVE-2024-31601

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform versions 20240323 and before
Description An issue in the Panalog big data analysis platform allows attackers to execute arbitrary code via the exportpdf.php component.
Recommendations For versions 20240323 and before, consider disabling the exportpdf.php component until a patch is available to prevent arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-31601

Affected Products

Analog