PT-2024-27798 · Unknown · Wbsairback

Alejandro Amorín Niño

+3

·

Published

2024-04-15

·

Updated

2024-05-14

·

CVE-2024-3787

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WBSAirback version 21.02.04
Description The issue involves improper neutralisation of Server-Side Includes (SSI) through S3 disks, specifically at the /admin/DeviceS3 endpoint. This could allow a remote user to execute arbitrary code, potentially leading to privilege escalation.
Recommendations For WBSAirback version 21.02.04, assess the impact of this issue, patch the system, and monitor for signs of exploitation. As a temporary workaround, consider restricting access to the /admin/DeviceS3 endpoint until a patch is available.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-3787

Affected Products

Wbsairback