FastAdmin Vulnerability: Remote Path Traversal Exploit Discovered and Disclosed
CVE-2024-7928

7.5HIGH

Key Information:

Vendor

FastAdmin

Status
Vendor
CVE Published:
19 August 2024

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC🟣 EPSS 16%πŸ“° News Worthy

What is CVE-2024-7928?

The FastAdmin software has a vulnerability (CVE-2024-7928) that allows for remote path traversal, potentially being exploited by unauthenticated attackers to execute a directory traversal. The issue affects FastAdmin up to version 1.3.3.20220121, and upgrading to version 1.3.4.20220530 is recommended to address this problem. There is a tool available for bulk scanning and exploiting instances of FastAdmin with this vulnerability, but use of this tool for unauthorized access is discouraged.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Bulk Scanning and Exploitation Tool for CVE-2024-7928 FastAdmin Instances

Bulk Scanning and Exploitation Tool for CVE-2024-7928 FastAdmin Instances

References

EPSS Score

16% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by darkwebinformer.com

  • Vulnerability published

.