C-MOR Video Surveillance System Vulnerable to OS Command Injection Attacks
CVE-2024-45179
What is CVE-2024-45179?
The C-MOR Video Surveillance system, specifically versions 5.2401 and 6.00PL01, contains a vulnerability that arises from insufficient input validation in its web interface. This flaw enables OS command injection attacks, allowing low-privileged authenticated users to execute arbitrary commands through crafted HTTP POST requests, particularly affecting functionalities like the generation of X.509 certificates. Additionally, an administrative user can exploit this vulnerability in scripts such as settimezone.pml and setdatetime.pml, which can lead to the execution of commands with elevated privileges. This makes the C-MOR system susceptible to critical security risks, which necessitates immediate attention and remediation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
