Skip to content
COOEY

EXPOSURES › CVE-2024-27348

CVE-2024-27348

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-09-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-27348 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildsupply-chain

Apache HugeGraph-Server allows remote arbitrary code execution via improper access control, enabling attackers to compromise graph databases used by defense systems.

Apache HugeGraph-Server contains a critical improper access control vulnerability (CVE-2024-27348) that permits remote attackers to execute arbitrary code, directly violating NIST 800-171 access control requirements. Defense contractors must immediately patch this vulnerability and audit all Apache HugeGraph deployments to prevent unauthorized code execution and data exfiltration.

Shame score — A critical RCE vulnerability in a graph database product used by defense systems was actively exploited and linked to ransomware campaigns, indicating negligent security posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.