Command Injection Vulnerability in Cohesive Networks VNS3
CVE-2024-8806

9.8CRITICAL

Key Information:

Status
Vendor
CVE Published:
22 November 2024

What is CVE-2024-8806?

The vulnerability in Cohesive Networks VNS3 arises from a flaw in its web service, which listens on TCP port 8000 by default. This flaw allows remote attackers to exploit the system by executing arbitrary code due to inadequate validation of a user-supplied input string before it is processed in a system call. As a result, unauthorized individuals can execute commands with root privileges, posing a significant risk to system integrity and confidentiality. Effective security measures and prompt updates are essential to mitigate this vulnerability and safeguard installations of Cohesive Networks VNS3.

Affected Version(s)

VNS3 6.2.3-20240417

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.