Command Injection Vulnerability in openEuler A-Tune-Collector on Linux
CVE-2024-24897

8.1HIGH

Key Information:

Vendor

Openeuler

Vendor
CVE Published:
25 March 2024

What is CVE-2024-24897?

A serious vulnerability exists within the openEuler A-Tune-Collector, affecting versions from 1.1.0-3 to 1.3.0. This vulnerability arises from improper neutralization of special elements used in command processing, which can lead to command injection attacks. By exploiting this flaw, an adversary could execute arbitrary commands in the system, potentially leading to unauthorized access or control over the affected systems. Users of A-Tune-Collector must take immediate action to update their installations to mitigate the risks posed by this vulnerability. For further details on the specific vulnerabilities and recommended patches, please refer to the official security bulletins and repositories.

Affected Version(s)

A-Tune-Collector Linux 1.1.0-3 <= 1.3.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

.