CVE-2024-7699OS Command Injection in Contact FL Mguard 2102

Severity
8.8HIGHNVD
EPSS
0.7%
top 27.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10

Description

An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages72 packages

🔴Vulnerability Details

2
GHSA
GHSA-chpx-369q-wwrx: An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data2024-09-10
CVEList
Phoenix Contact: OS command execution in MGUARD products2024-09-10
CVE-2024-7699 — OS Command Injection | cvebase