CVE-2024-11482: OS Command Injection
Published Nov 29, 2024
·Updated
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.
Affected Software
2 affected components
esm ESM
Trellix Enterprise Security Manager=11.6.10
Event History
Nov 29, 2024
CVE Published
via MITRE·07:03 AM
Data Sourced
via MITRE·07:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-11482?
CVE-2024-11482 has a critical severity rating due to the potential for unauthenticated remote code execution.
2
How do I fix CVE-2024-11482?
To mitigate CVE-2024-11482, update ESM to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2024-11482?
CVE-2024-11482 affects ESM version 11.6.10.
4
What kind of attack can CVE-2024-11482 enable?
CVE-2024-11482 can enable remote code execution through command injection.
5
Is there a workaround for CVE-2024-11482?
Currently, no specific workarounds are documented for CVE-2024-11482; upgrading is recommended.