Remote Code Execution Vulnerability in A10 Thunder ADC CsrRequestView Class
CVE-2024-30368

8.8HIGH

Key Information:

Vendor
A10
Status
Thunder Adc
Vendor
CVE Published:
6 June 2024

Summary

A vulnerability exists in the A10 Thunder ADC affecting the CsrRequestView class, which allows remote, authenticated attackers to execute arbitrary code on affected installations. The flaw arises from improper validation of user-supplied input, allowing for the execution of system calls inappropriately. Exploitation of this vulnerability could enable attackers to compromise system integrity and perform unwanted actions under the privileges of the a10user account. Robust security measures are essential to mitigate risks associated with this vulnerability.

Affected Version(s)

Thunder ADC 6.0.2, build 68

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.