CVE-2024-8073
Hillstone Networks Web Application Firewall Command Injection Vulnerability
Description
Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks Web Application Firewall: from 5.5R6-2.6.7 through 5.5R6-2.8.13.
INFO
Published Date :
Aug. 26, 2024, 3:15 a.m.
Last Modified :
Sept. 12, 2024, 8:58 p.m.
Source :
[email protected]
Remotely Exploitable :
Yes !
Impact Score :
5.9
Exploitability Score :
3.9
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2024-8073
.
URL | Resource |
---|---|
https://www.hillstonenet.com.cn/security-notification/2024/08/21/mlzrld-2/ | Vendor Advisory |
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2024-8073
vulnerability anywhere in the article.
- Cybersecurity News
CVE-2024-8698: Keycloak Vulnerability Puts SAML Authentication at Risk
Image: KeycloakIn a concerning development for organizations relying on Keycloak for secure identity and access management, a high-severity vulnerability has been discovered in its SAML signature vali ... Read more
- Cybersecurity News
Rockwell Automation Products Face Critical Security Risks, Urgent Patching Required
Two recently discovered vulnerabilities in Rockwell Automation’s FactoryTalk software products pose a serious threat to industrial control systems (ICS). The vulnerabilities, tracked as CVE-2024-45823 ... Read more
- Cybersecurity News
CVE-2024-28991 (CVSS 9.0): SolarWinds Access Rights Manager RCE Flaw
In a recent security advisory, SolarWinds has disclosed two vulnerabilities affecting their Access Rights Manager (ARM) software. ARM is widely used by IT and security administrators to manage and aud ... Read more
- Cybersecurity News
CVE-2024-38811: Code Execution Vulnerability Discovered in VMware Fusion
A high-severity security vulnerability (CVE-2024-38811, CVSS 8.8) has been identified in VMware Fusion, a popular virtualization software for macOS. The vulnerability, discovered by Mykola Grymalyuk o ... Read more
- Cybersecurity News
CVE-2024-7593 (CVSS 9.8): Critical Ivanti vTM Flaw Now Weaponized, PoC Exploit Available
A critical authentication bypass vulnerability, tracked as CVE-2024-7593 (CVSS 9.8), in Ivanti’s Virtual Traffic Manager (vTM), is now significantly easier to exploit thanks to the release of public p ... Read more
- Cybersecurity News
WikiLoader Malware Evolves with SEO Poisoning, Targets GlobalProtect Users
A cloned GlobalProtect page that directs users to download spoofed GlobalProtect installers | Image: Unit 42Please enable JavaScriptIn a recent investigation, the Unit 42 Managed Threat Hunting (MTH) ... Read more
- Cybersecurity News
Hillstone Networks Addresses Critical RCE Vulnerability in WAF (CVE-2024-8073, CVSS 9.8)
Hillstone Networks, a global leader in network security solutions, has released a security advisory addressing a critical vulnerability (CVE-2024-8073) in its Web Application Firewall (WAF) product. T ... Read more
The following table lists the changes that have been made to the
CVE-2024-8073
vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Sep. 12, 2024
Action Type Old Value New Value Added CVSS V3.1 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Changed Reference Type https://www.hillstonenet.com.cn/security-notification/2024/08/21/mlzrld-2/ No Types Assigned https://www.hillstonenet.com.cn/security-notification/2024/08/21/mlzrld-2/ Vendor Advisory Added CWE NIST CWE-77 Added CPE Configuration OR *cpe:2.3:a:hillstonenet:web_application_firewall:5.5r6-2.6.7:*:*:*:*:*:*:* *cpe:2.3:a:hillstonenet:web_application_firewall:5.5r6-2.8.13:*:*:*:*:*:*:* -
CVE Received by [email protected]
Aug. 26, 2024
Action Type Old Value New Value Added Description Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks Web Application Firewall: from 5.5R6-2.6.7 through 5.5R6-2.8.13. Added Reference Hillstone Networks, Inc. https://www.hillstonenet.com.cn/security-notification/2024/08/21/mlzrld-2/ [No types assigned] Added CWE Hillstone Networks, Inc. CWE-20 Added CVSS V3.1 Hillstone Networks, Inc. AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2024-8073
is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2024-8073
weaknesses.