← volver
CVE-2023-7304criticalexplotación observadaCWE-78

Ruijie RG-UAC nmc_sync.php Command Injection

70Vexday Risk Score

Prioriza la corrección. Ella explotación observada por VulnCheck y tiene prueba de concepto pública.

ssvc Actcvss 9.3epss 3.6%
de la publicación al arma
Publicada en NVD15 oct
VulnCheck14 oct
probabilidad de explotación
3.6%top 12% de las CVE
explotación observada
VulnCheck
1 exploit(s) público(s)
Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker able to reach the affected endpoint can inject shell commands via crafted request data, causing the application to execute arbitrary commands on the host. Successful exploitation can yield full control of the application process and may lead to system-level access depending on the service privileges. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.