Low-Privileged User Can Execute Arbitrary Code Remotely on Device with High Privileges
CVE-2024-2162
What is CVE-2024-2162?
An OS Command Injection vulnerability exists in Kiloview's NDI products that allows low-privileged users to remotely execute arbitrary code with elevated privileges on affected devices. This flaw can be exploited to compromise system integrity and confidentiality, making it crucial for users to apply the recent firmware update, version 2.02.0227, to mitigate the risks associated with this vulnerability. Devices impacted include the Kiloview NDI N3, N3-s, N4, N20, N30, and N40, emphasizing the need for immediate attention from those utilizing these products.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
NDI N3 Firmware 2.02.0227
NDI N3 Firmware 2.02.0227
NDI N3-s Firmware 2.02.0227
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
