216.73.216.233

CVE-2024-22116

· Published 12/08/2024 13:38 · Modified 12/08/2024 13:41

Labels: CVE-2024-22116 2024-08-12CVE-2024-22116CWE-94[email protected]

Essential information

Published
12/08/2024 13:38
Modified
12/08/2024 13:41
Author
Creator
CVSS
9.9 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References