CVE-2024-4163
Last modified
CVE-2024-4163 is a high-severity vulnerability rated 8/10 on the CVSS scale. The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovered that the process was running under root privileges. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovered that the process was running under root privileges. This allowed the attacker to read, write, and modify any file in the operating system by utilizing the limited shell file exec and download functions. By replacing the /etc/passwd file with a new root user entry, the attacker was able to breakout from the limited shell and login to a unrestricted shell with root access. With the root access, the attacker will be able take full control of the IIoT Gateway.
Metrics
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-4163?
How severe is CVE-2024-4163?
How do I fix CVE-2024-4163?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-4162A buffer error in Panasonic KW Watcher versions 1.00 through…4.4
- CVE-2024-41622D-Link DIR-846W A1 FW100A43 was discovered to contain a remo…9.8
- CVE-2024-41623An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4…9.8
- CVE-2024-41624Incorrect access control in Himalaya Xiaoya nano smart speak…6.3
- CVE-2024-41628Directory Traversal vulnerability in Severalnines Cluster Co…7.5
- CVE-2024-41629An issue in Texas Instruments Fusion Digital Power Designer …5.5
- CVE-2024-41630Stack-based buffer overflow vulnerability in Tenda AC18 V15.…7.6
- CVE-2024-41631Buffer Overflow vulnerability in host-host NEUQ_board v.1.0 …7.5
- CVE-2024-41637RaspAP before 3.1.5 allows an attacker to escalate privilege…8.3
- CVE-2024-4164A vulnerability, which was classified as critical, has been …9.8
- CVE-2024-41640Cross Site Scripting (XSS) vulnerability in AML Surety Eco u…6.1
- CVE-2024-41643An issue in Arris NVG443B 9.3.0h3d36 allows a physically pro…6.8
Are you affected by CVE-2024-4163?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
