CVE-2024-12987
Last modified
CVE-2024-12987 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. CISA has confirmed active exploitation in the wild. EPSS estimates a 98.13% chance of exploitation in the next 30 days.
Description
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Draytek | Vigor300b Firmware | 1.5.1.4 |
| Draytek | Vigor2960 Firmware | 1.5.1.4 |
References
- https://vuldb.com/?ctiid.289380Permissions Required, VDB Entry
- https://vuldb.com/?id.289380Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.468795Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-12987US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-12987?
How severe is CVE-2024-12987?
How do I fix CVE-2024-12987?
Are you affected by CVE-2024-12987?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
