CVE-2024-23692criticalunder attackransomwareCWE-1336

CVE-2024-23692: critical vulnerability in Rejetto HTTP File Server

Rejetto HTTP File Server 2.3m Unauthenticated RCE

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 99%
from disclosure to weapon11 days
Published on NVDMay 31
1st PoC+11d
metasploitMay 25
CISA KEV+39d
exploitation probability
99%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
27 public exploit(s)
Action required by CISAfederal deadline: 2024-07-30

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

Rejetto HTTP File Server version 2.3m and earlier has a critical flaw that allows anyone on the internet to run malicious commands on the affected computer by sending a specially crafted request. No login is required, making it extremely dangerous.

Technical detail

A template injection vulnerability in Rejetto HFS ≤2.3m enables unauthenticated remote code execution via crafted HTTP requests. The vulnerability stems from improper template processing that fails to sanitize user input, allowing an attacker to inject and execute arbitrary commands on the host system without authentication.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.