Remote Code Execution Vulnerability in A10 Thunder ADC CsrRequestView Class
CVE-2024-30368
8.8HIGH
Summary
A vulnerability exists in the A10 Thunder ADC affecting the CsrRequestView class, which allows remote, authenticated attackers to execute arbitrary code on affected installations. The flaw arises from improper validation of user-supplied input, allowing for the execution of system calls inappropriately. Exploitation of this vulnerability could enable attackers to compromise system integrity and perform unwanted actions under the privileges of the a10user account. Robust security measures are essential to mitigate risks associated with this vulnerability.
Affected Version(s)
Thunder ADC 6.0.2, build 68
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database