CVE-2024-45448
published 2024-09-04CVE-2024-45448: Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may affect service…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.10%
1.0th percentile
Page table protection configuration vulnerability in the trusted firmware module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | emui | — | — |
| huawei | harmonyos | — | — |
| huawei | harmonyos | — | — |
| huawei | harmonyos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT LG SuperSign EZ CMS 2.5 Remote Code Execution CVE-2018-17173
suricata·2020-06-11·CVSS 9.8
CVE-2018-17173 [CRITICAL] ET EXPLOIT LG SuperSign EZ CMS 2.5 Remote Code Execution CVE-2018-17173
ET EXPLOIT LG SuperSign EZ CMS 2.5 Remote Code Execution CVE-2018-17173
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT LG SuperSign EZ CMS 2.5 Remote Code Execution CVE-2018-17173"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/qsr_server/device/getThumbnail?sourceUri="; fast_pattern; content:"'&targetUri="; distance:0; reference:url,www.exploit-db.com/exploits/45448; reference:cve,2018-17173; classtype:attempted-admin; sid:2030317; rev:3; metadata:affected_product Linux, attack_target IoT, created_at 2020_06_11, cve CVE_2018_17173, deployment Perimeter, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_07, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique
Suricata
ET EXPLOIT Possible LG SuperSign EZ CMS 2.5 RCE (CVE-2018-17173)
suricata·2019-03-18·CVSS 9.8
CVE-2018-17173 [CRITICAL] ET EXPLOIT Possible LG SuperSign EZ CMS 2.5 RCE (CVE-2018-17173)
ET EXPLOIT Possible LG SuperSign EZ CMS 2.5 RCE (CVE-2018-17173)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET 9080 (msg:"ET EXPLOIT Possible LG SuperSign EZ CMS 2.5 RCE (CVE-2018-17173)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/qsrserver/device/getThumbnail?sourceUri=|22|"; startswith; fast_pattern; content:"|3b|"; within:40; content:"&targetUri="; distance:0; content:"&scaleType="; distance:0; reference:url,www.exploit-db.com/exploits/45448; reference:cve,2018-17173; classtype:attempted-admin; sid:2027089; rev:6; metadata:attack_target IoT, created_at 2019_03_18, cve CVE_2018_17173, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, updated_at 2024_04_13;)
No public exploits indexed.
No writeups or analysis indexed.
2024-09-04
Published