CVE-2024-7694
גבוהה 7.2 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
מדדים
- CVSS 3.1
-
7.2 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 2% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-434
מוצרים מושפעים
teamt5: threatsonar anti-ransomware
קישורים
- https://www.twcert.org.tw/en/cp-139-8000-e5a5c-2.html Third Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7998-d76dd-1.html Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource