PT-2024-29965 · Cometvisu+1 · Cometvisu+1
P-
·
Published
2024-08-09
·
Updated
2024-09-12
·
CVE-2024-42469
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openHAB versions prior to 4.2.1
Description
The issue concerns the CometVisu add-on of openHAB, which has file system endpoints that do not require authentication. Additionally, the endpoint to update an existing file is susceptible to path traversal, making it possible for an attacker to overwrite existing files on the openHAB instance. If the overwritten file is a shell script that is executed at a later time, this can allow remote code execution by an attacker.
Recommendations
For openHAB versions prior to 4.2.1, upgrade to version 4.2.1 to receive a patch. As a temporary workaround, consider restricting access to the file system endpoints to minimize the risk of exploitation. Avoid using the endpoint to update an existing file until the issue is resolved.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cometvisu
Openhab