CVE-2024-24091: OS Command Injection
Published Feb 8, 2024
·Updated
Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.
Affected Software
1 affected component
Yealink Yealink Meeting Server<26.0.0.66
Event History
Feb 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24091?
CVE-2024-24091 is rated as a high severity vulnerability due to its potential for OS command injection.
2
How do I fix CVE-2024-24091?
To fix CVE-2024-24091, users should update Yealink Meeting Server to version 26.0.0.66 or later.
3
What does CVE-2024-24091 affect?
CVE-2024-24091 affects all versions of Yealink Meeting Server prior to 26.0.0.66.
4
What type of vulnerability is CVE-2024-24091?
CVE-2024-24091 is an OS command injection vulnerability that can be exploited via the file upload interface.
5
When was CVE-2024-24091 disclosed?
CVE-2024-24091 was disclosed as a vulnerability prior to the release of the fixed version on Yealink's official channels.