PT-2024-29353 · It Solutions · It Solutions Enjay Crm Os

Aamir Rehman

·

Published

2024-08-07

·

Updated

2024-08-08

·

CVE-2024-41308

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IT Solutions Enjay CRM OS version 1.0
Description The issue in the Ping feature allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.
Recommendations For IT Solutions Enjay CRM OS version 1.0, consider disabling the Ping feature as a temporary workaround until a patch is available. Restrict access to the terminal environment to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-41308

Affected Products

It Solutions Enjay Crm Os