CVE-2024-2413
Last modified
CVE-2024-2413 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string composed of the user's name and timestamp to generate an authentication code. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string composed of the user's name and timestamp to generate an authentication code. With this authentication code, they can obtain administrator privileges and subsequently execute arbitrary code on the remote server using built-in system functionality.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intumit | Smartrobot | < 6.2.0-202303TW |
References
- https://www.twcert.org.tw/tw/cp-132-7697-ecf10-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7697-ecf10-1.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-2413?
How severe is CVE-2024-2413?
How do I fix CVE-2024-2413?
Are you affected by CVE-2024-2413?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
