2024-08-30 04:03:15 +00:00
{
"id" : "CVE-2024-8329" ,
"sourceIdentifier" : "twcert@cert.org.tw" ,
"published" : "2024-08-30T03:15:04.463" ,
2024-09-05 14:03:46 +00:00
"lastModified" : "2024-09-05T13:40:38.080" ,
"vulnStatus" : "Analyzed" ,
2024-08-30 04:03:15 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents."
2024-08-30 14:03:14 +00:00
} ,
{
"lang" : "es" ,
"value" : "El sistema 6SHR de Gether Technology no valida correctamente el par\u00e1metro de p\u00e1gina espec\u00edfico, lo que permite a atacantes remotos con privilegios regulares inyectar comandos SQL para leer, modificar y eliminar contenidos de la base de datos."
2024-08-30 04:03:15 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "twcert@cert.org.tw" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "twcert@cert.org.tw" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-89"
}
]
}
] ,
2024-09-05 14:03:46 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:6shr_system_project:6shr_system:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A5EDAD84-3FBF-46BF-9947-1186D09D9E90"
}
]
}
]
}
] ,
2024-08-30 04:03:15 +00:00
"references" : [
{
"url" : "https://www.twcert.org.tw/en/cp-139-8034-657b7-2.html" ,
2024-09-05 14:03:46 +00:00
"source" : "twcert@cert.org.tw" ,
"tags" : [
"Vendor Advisory"
]
2024-08-30 04:03:15 +00:00
} ,
{
"url" : "https://www.twcert.org.tw/tw/cp-132-8030-e2eac-1.html" ,
2024-09-05 14:03:46 +00:00
"source" : "twcert@cert.org.tw" ,
"tags" : [
"Vendor Advisory"
]
2024-08-30 04:03:15 +00:00
}
]
}