CVE-2024-41783

CWE-77Command Injection3 documents3 sources
Severity
9.1CRITICAL
EPSS
0.3%
top 51.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 19

Description

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 2.3 | Impact: 6.0

Affected Packages2 packages

NVDibm/sterling_secure_proxy6.0.0.06.0.3.1+2
CVEListV5ibm/sterling_secure_proxy6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, 6.2.0.0

🔴Vulnerability Details

2
CVEList
IBM Sterling Secure Proxy improper input validation2025-01-19
GHSA
GHSA-6mh8-832j-gc49: IBM Sterling Secure Proxy 62025-01-19
CVE-2024-41783 (CRITICAL CVSS 9.1) | IBM Sterling Secure Proxy 6.0.0.0 | cvebase.io