PT-2024-30545 · Mguard · Mguard
Andrea Palanca
·
Published
2024-09-10
·
Updated
2024-09-27
·
CVE-2024-43385
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
mGuard devices (affected versions not specified)
Description
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable
PROXY HTTP PORT. This allows remote attackers to execute OS commands as root via manipulation of the PROXY HTTP PORT variable.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the
PROXY HTTP PORT variable to minimize the risk of exploitation. Avoid using the PROXY HTTP PORT variable in sensitive operations until the issue is resolved.OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mguard