Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-7579", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2024-08-07T06:37:55.279Z", "datePublished": "2024-08-07T14:00:08.086Z", "dateUpdated": "2024-08-07T15:24:06.724Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2024-08-07T14:00:08.086Z"}, "title": "Alien Technology ALR-F800 File Name upgrade.cgi popen os command injection", "problemTypes": [{"descriptions": [{"type": "CWE", "cweId": "CWE-78", "lang": "en", "description": "CWE-78 OS Command Injection"}]}], "affected": [{"vendor": "Alien Technology", "product": "ALR-F800", "versions": [{"version": "19.10.0", "status": "affected"}, {"version": "19.10.1", "status": "affected"}, {"version": "19.10.2", "status": "affected"}, {"version": "19.10.3", "status": "affected"}, {"version": "19.10.4", "status": "affected"}, {"version": "19.10.5", "status": "affected"}, {"version": "19.10.6", "status": "affected"}, {"version": "19.10.7", "status": "affected"}, {"version": "19.10.8", "status": "affected"}, {"version": "19.10.9", "status": "affected"}, {"version": "19.10.10", "status": "affected"}, {"version": "19.10.11", "status": "affected"}, {"version": "19.10.12", "status": "affected"}, {"version": "19.10.13", "status": "affected"}, {"version": "19.10.14", "status": "affected"}, {"version": "19.10.15", "status": "affected"}, {"version": "19.10.16", "status": "affected"}, {"version": "19.10.17", "status": "affected"}, {"version": "19.10.18", "status": "affected"}, {"version": "19.10.19", "status": "affected"}, {"version": "19.10.20", "status": "affected"}, {"version": "19.10.21", "status": "affected"}, {"version": "19.10.22", "status": "affected"}, {"version": "19.10.23", "status": "affected"}, {"version": "19.10.24", "status": "affected"}], "modules": ["File Name Handler"]}], "descriptions": [{"lang": "en", "value": "A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the function popen of the file /var/www/cgi-bin/upgrade.cgi of the component File Name Handler. The manipulation of the argument uploadedFile leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way."}, {"lang": "de", "value": "In Alien Technology ALR-F800 bis 19.10.24.00 wurde eine kritische Schwachstelle ausgemacht. Hierbei betrifft es die Funktion popen der Datei /var/www/cgi-bin/upgrade.cgi der Komponente File Name Handler. Durch die Manipulation des Arguments uploadedFile mit unbekannten Daten kann eine os command injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff \u00fcber das Netzwerk. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."}], "metrics": [{"cvssV4_0": {"version": "4.0", "baseScore": 5.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N", "baseSeverity": "MEDIUM"}}, {"cvssV3_1": {"version": "3.1", "baseScore": 6.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "baseSeverity": "MEDIUM"}}, {"cvssV3_0": {"version": "3.0", "baseScore": 6.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "baseSeverity": "MEDIUM"}}, {"cvssV2_0": {"version": "2.0", "baseScore": 6.5, "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P"}}], "timeline": [{"time": "2024-08-07T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed"}, {"time": "2024-08-07T02:00:00.000Z", "lang": "en", "value": "VulDB entry created"}, {"time": "2024-08-07T08:43:12.000Z", "lang": "en", "value": "VulDB entry last update"}], "credits": [{"lang": "en", "value": "PushEAX (VulDB User)", "type": "reporter"}], "references": [{"url": "https://vuldb.com/?id.273859", "name": "VDB-273859 | Alien Technology ALR-F800 File Name upgrade.cgi popen os command injection", "tags": ["vdb-entry", "technical-description"]}, {"url": "https://vuldb.com/?ctiid.273859", "name": "VDB-273859 | CTI Indicators (IOB, IOC, TTP, IOA)", "tags": ["signature", "permissions-required"]}, {"url": "https://vuldb.com/?submit.382470", "name": "Submit #382470 | Alien Technology ALR-F800 19.10.24.00 and lower OS Command Injection", "tags": ["third-party-advisory"]}, {"url": "https://github.com/Push3AX/vul/blob/main/Alien%20Technology%20/ALR-F800.md", "tags": ["exploit"]}]}, "adp": [{"affected": [{"vendor": "alientechnology", "product": "alr-f800", "cpes": ["cpe:2.3:a:alientechnology:alr-f800:*:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "0", "status": "affected", "lessThan": "19.10.24.00", "versionType": "custom"}]}], "metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-08-07T15:15:02.386565Z", "id": "CVE-2024-7579", "options": [{"Exploitation": "poc"}, {"Automatable": "no"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-08-07T15:24:06.724Z"}}]}}