PT-2024-28798 · Byzoro · Byzoro Smart S80 Management Platform

Scausoft

·

Published

2024-04-20

·

Updated

2024-06-04

·

CVE-2024-4019

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Byzoro Smart S80 Management Platform versions up to 20240411
Description A critical vulnerability has been found in the Byzoro Smart S80 Management Platform. The issue affects an unknown function of the file /importhtml.php. The manipulation of the sql argument leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For versions up to 20240411, as a temporary workaround, consider restricting access to the /importhtml.php file until a patch is available. Avoid using the sql argument in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4019

Affected Products

Byzoro Smart S80 Management Platform