CVE-2024-4504
Last modified
CVE-2024-4504 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240428. Affected by this issue is some unknown functionality of the file /view/HAconfig/baseConfig/commit.php. EPSS estimates a 6.70% chance of exploitation in the next 30 days.
Description
A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240428. Affected by this issue is some unknown functionality of the file /view/HAconfig/baseConfig/commit.php. The manipulation of the argument peer_ip/local_ip leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263108. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ruijie | Rg-Uac 6000-Cc Firmware | All versions |
| Ruijie | Rg-Uac 6000-E10 Firmware | All versions |
| Ruijie | Rg-Uac 6000-E10c Firmware | All versions |
| Ruijie | Rg-Uac 6000-E20 Firmware | All versions |
| Ruijie | Rg-Uac 6000-E20c Firmware | All versions |
| Ruijie | Rg-Uac 6000-E20m Firmware | All versions |
| Ruijie | Rg-Uac 6000-E50 Firmware | All versions |
| Ruijie | Rg-Uac 6000-E50c Firmware | All versions |
| Ruijie | Rg-Uac 6000-E50m Firmware | All versions |
| Ruijie | Rg-Uac 6000-Ea Firmware | All versions |
| Ruijie | Rg-Uac 6000-Ei Firmware | All versions |
| Ruijie | Rg-Uac 6000-Isg02 Firmware | All versions |
| Ruijie | Rg-Uac 6000-Isg10 Firmware | All versions |
| Ruijie | Rg-Uac 6000-Isg200 Firmware | All versions |
| Ruijie | Rg-Uac 6000-Isg40 Firmware | All versions |
| Ruijie | Rg-Uac 6000-Si Firmware | All versions |
| Ruijie | Rg-Uac 6000-U3100 Firmware | All versions |
| Ruijie | Rg-Uac 6000-U3210 Firmware | All versions |
| Ruijie | Rg-Uac 6000-X100 Firmware | All versions |
| Ruijie | Rg-Uac 6000-X100s Firmware | All versions |
| Ruijie | Rg-Uac 6000-X20 Firmware | All versions |
| Ruijie | Rg-Uac 6000-X200 Firmware | All versions |
| Ruijie | Rg-Uac 6000-X20m Firmware | All versions |
| Ruijie | Rg-Uac 6000-X20me Firmware | All versions |
| Ruijie | Rg-Uac 6000-X300d Firmware | All versions |
| Ruijie | Rg-Uac 6000-X60 Firmware | All versions |
| Ruijie | Rg-Uac 6000-Xs Firmware | All versions |
References
- https://vuldb.com/?ctiid.263108Permissions Required, VDB Entry
- https://vuldb.com/?id.263108Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.323814Third Party Advisory, VDB Entry
- https://vuldb.com/?ctiid.263108Permissions Required, VDB Entry
- https://vuldb.com/?id.263108Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.323814Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-4504?
How severe is CVE-2024-4504?
How do I fix CVE-2024-4504?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45033Insufficient Session Expiration vulnerability in Apache Airf…8.1
- CVE-2024-45034Apache Airflow versions before 2.10.1 have a vulnerability t…8.8
- CVE-2024-45036Tophat is a mobile applications testing harness. An Improper…4.3
- CVE-2024-45037The AWS Cloud Development Kit (CDK) is an open-source framew…6.4
- CVE-2024-45038Meshtastic device firmware is a firmware for meshtastic devi…7.5
- CVE-2024-45039gnark is a fast zk-SNARK library that offers a high-level AP…6.2
- CVE-2024-45040gnark is a fast zk-SNARK library that offers a high-level AP…5.9
- CVE-2024-45041External Secrets Operator is a Kubernetes operator that inte…8.8
- CVE-2024-45042Ory Kratos is an identity, user management and authenticatio…4.4
- CVE-2024-45043The OpenTelemetry Collector module AWS firehose receiver is …5.3
- CVE-2024-45044Bareos is open source software for backup, archiving, and re…8.8
- CVE-2024-45045Collabora Online is a collaborative online office suite base…6.1
Are you affected by CVE-2024-4504?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
