CometVisu Vulnerability: Remote Code Execution
CVE-2024-42469

9.8CRITICAL

Key Information:

Vendor

Openhab

Vendor
CVE Published:
12 August 2024

What is CVE-2024-42469?

The CometVisu visualization add-on for openHAB, prior to version 4.2.1, contains vulnerabilities that expose file system endpoints without required authentication. An attacker exploiting this flaw can perform path traversal attacks, allowing them to overwrite essential files within the openHAB instance. If a compromised file includes a shell script, it could be executed in the future, enabling potential remote code execution. Users are strongly advised to update to version 4.2.1 to mitigate these security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

openhab-webui < 4.2.1

References

EPSS Score

13% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.