Skip to content
COOEY

EXPOSURES › CVE-2024-23692

CVE-2024-23692

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-07-09 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-23692 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Rejetto HTTP File Server allows remote, unauthenticated attackers to execute arbitrary commands via template engine injection.

This vulnerability enables remote code execution without authentication, posing a severe risk to DIB systems hosting sensitive data. Organizations must immediately patch or disable the affected product to prevent unauthorized access and potential data exfiltration.

Shame score — A remote, unauthenticated RCE vulnerability in a widely deployed file server product indicates a critical security oversight that could lead to widespread compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.