CVE-2024-41226
Last modified
CVE-2024-41226 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack the Control Room. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack the Control Room. The payload is being injected in the http Response from the client-side, so the owner of the Response and payload is the end user in this case. They contend that the server's security controls have no impact or role to play in this situation and therefore this is not a valid vulnerability.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Automationanywhere | Automation 360 | 21094 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-41226?
How severe is CVE-2024-41226?
How do I fix CVE-2024-41226?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-41200A segmentation fault in KMPlayer v4.2.2.65 allows attackers …5.5
- CVE-2024-41206A stack-based buffer over-read in tsMuxer version nightly-20…6.5
- CVE-2024-41209A heap-based buffer overflow in tsMuxer version nightly-2024…8.8
- CVE-2024-4121A vulnerability classified as critical has been found in Ten…8.8
- CVE-2024-41217A heap-based buffer overflow in tsMuxer version nightly-2024…6.5
- CVE-2024-4122A vulnerability classified as critical was found in Tenda W1…8.8
- CVE-2024-41228A symlink following vulnerability in the pouch cp function o…7.6
- CVE-2024-4123A vulnerability, which was classified as critical, has been …8.8
- CVE-2024-41236A SQL injection vulnerability in /smsa/admin_login.php in Ka…7.2
- CVE-2024-41237A SQL injection vulnerability in /smsa/teacher_login.php in …9.8
- CVE-2024-41238A SQL injection vulnerability in /smsa/student_login.php in …5.3
- CVE-2024-41239A Stored Cross Site Scripting (XSS) vulnerability was found …4.8
Are you affected by CVE-2024-41226?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
