CVE-2020-24384: Critical severity a10 networks agalaxy vulnerability
A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affected ACOS systems. ACOS versions 3.2.x (including and after 3.2.2), 4.x, and 5.1.x are affected. aGalaxy versions 3.0.x, 3.2.x, and 5.0.x are affected.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-24384?
CVE-2020-24384 is a critical vulnerability in A10 Networks ACOS and aGalaxy management GUIs that allows unauthenticated remote code execution.
Which systems are affected by CVE-2020-24384?
ACOS versions 3.2.x (including and after 3.2.2), 4.x, and 5.1.x are affected. aGalaxy versions 3.0.x, 3.2.1-3.2.4, and 5.0.1-5.0.5 are also affected.
What is the severity of CVE-2020-24384?
CVE-2020-24384 has a severity rating of 9.8, which is considered critical.
How can I fix CVE-2020-24384?
To fix CVE-2020-24384, it is recommended to upgrade to the latest patched version of ACOS or aGalaxy as provided by A10 Networks.
Where can I find more information about CVE-2020-24384?
You can find more information about CVE-2020-24384 on the A10 Networks security advisory page at https://support.a10networks.com/support/security_advisory/acos-agalaxy-gui-rce-vulnerability-cve-2020-24384.