Command Injection Vulnerability in Cohesive Networks VNS3
CVE-2024-8806
9.8CRITICAL
What is CVE-2024-8806?
The vulnerability in Cohesive Networks VNS3 arises from a flaw in its web service, which listens on TCP port 8000 by default. This flaw allows remote attackers to exploit the system by executing arbitrary code due to inadequate validation of a user-supplied input string before it is processed in a system call. As a result, unauthorized individuals can execute commands with root privileges, posing a significant risk to system integrity and confidentiality. Effective security measures and prompt updates are essential to mitigate this vulnerability and safeguard installations of Cohesive Networks VNS3.
Affected Version(s)
VNS3 6.2.3-20240417
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
