2024-12-15 03:03:56 +00:00

87 lines
2.4 KiB
JSON

{
"id": "CVE-2024-8330",
"sourceIdentifier": "twcert@cert.org.tw",
"published": "2024-08-30T03:15:04.660",
"lastModified": "2024-09-05T13:41:33.667",
"vulnStatus": "Analyzed",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server."
},
{
"lang": "es",
"value": "El sistema 6SHR de Gether Technology no valida correctamente los tipos de archivos cargados, lo que permite a atacantes remotos con privilegios regulares cargar scripts de shell web y usarlos para ejecutar comandos de sistema arbitrarios en el servidor."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "twcert@cert.org.tw",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "twcert@cert.org.tw",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-434"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:6shr_system_project:6shr_system:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A5EDAD84-3FBF-46BF-9947-1186D09D9E90"
}
]
}
]
}
],
"references": [
{
"url": "https://www.twcert.org.tw/en/cp-139-8035-53926-2.html",
"source": "twcert@cert.org.tw",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-8031-a2f21-1.html",
"source": "twcert@cert.org.tw",
"tags": [
"Vendor Advisory"
]
}
]
}