Remote Code Execution Vulnerability in A10 Thunder ADC CsrRequestView Class
CVE-2024-30368
8.8HIGH
What is CVE-2024-30368?
A vulnerability exists in the A10 Thunder ADC affecting the CsrRequestView class, which allows remote, authenticated attackers to execute arbitrary code on affected installations. The flaw arises from improper validation of user-supplied input, allowing for the execution of system calls inappropriately. Exploitation of this vulnerability could enable attackers to compromise system integrity and perform unwanted actions under the privileges of the a10user account. Robust security measures are essential to mitigate risks associated with this vulnerability.
Affected Version(s)
Thunder ADC 6.0.2, build 68
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
