PT-2024-29133 · Ffri · Ffri Amc
Published
2024-07-30
·
Updated
2024-08-01
·
CVE-2024-40895
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
FFRI AMC versions 3.4.0 to 3.5.3
Some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3
Description
The issue allows a remote unauthenticated attacker to execute arbitrary OS commands when certain conditions are met in an environment where the notification program setting is enabled and the executable file path is set to a batch file (.bat) or command file (.cmd) extension.
Recommendations
For FFRI AMC versions 3.4.0 to 3.5.3, consider disabling the notification program setting until a patch is available.
For some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3, restrict the executable file path to prevent setting it to a batch file (.bat) or command file (.cmd) extension.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ffri Amc