CVE-2024-13089: Authenticated RCE in update functionality in Guardian/CMC before 24.6.0
An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execute unauthorized arbitrary OS commands.
Users with administrative privileges may upload update packages to upgrade the versions of Nozomi Networks Guardian and CMC.
While these updates are signed and their signatures are validated prior to installation, an improper signature validation check has been identified.
This issue could potentially enable users to execute commands remotely on the appliance, thereby impacting confidentiality, integrity, and availability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13089?
CVE-2024-13089 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-13089?
To remediate CVE-2024-13089, apply the latest security patches provided by Nozomi Networks for Guardian and CMC.
Who is affected by CVE-2024-13089?
CVE-2024-13089 affects users with administrative privileges who can upload update packages for Nozomi Networks Guardian and CMC.
What types of attacks can CVE-2024-13089 enable?
CVE-2024-13089 enables attackers to execute unauthorized OS commands on the server where the affected software is installed.
Is user authentication required to exploit CVE-2024-13089?
Yes, CVE-2024-13089 requires user authentication as it can only be exploited by authenticated administrators.