EXPOSURES › CVE-2024-23692
CVE-2024-23692
HIGH ⌖ ON CISA KEV · EXPLOITEDRejetto HTTP File Server allows remote, unauthenticated attackers to execute arbitrary commands via template engine injection.
This vulnerability enables remote code execution without authentication, posing a severe risk to DIB systems hosting sensitive data. Organizations must immediately patch or disable the affected product to prevent unauthorized access and potential data exfiltration.
Shame score — A remote, unauthenticated RCE vulnerability in a widely deployed file server product indicates a critical security oversight that could lead to widespread compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.