CVE-2024-7443
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Aug 3, 2024
Updated: Aug 6, 2024
CWE ID 77
Summary
CVE-2024-7443 is a newly discovered critical vulnerability affecting the Vivotek IB8367A VVTK-0100b model. The issue lies in the getenv function of the file upload_file.cgi, where manipulation of the QUERY_STRING argument results in command injection. This vulnerability can be exploited remotely. However, it is important to note that this vulnerability only affects unsupported versions of the product, as confirmed by Vivotek. The vendor has also acknowledged that the affected release tree has reached its end-of-life.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share