CVE-2024-28753: Medium severity RaspAP raspap-webgui vulnerability
Published Mar 8, 2024
·Updated
RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to read the /etc/passwd file via a crafted request.
Affected Software
2 affected components
RaspAP raspap-webgui<3.0.9
RaspAP RaspAP<=3.0.9
Event History
Mar 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Apr 1, 58713
Event
via FIRST·08:29 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-28753?
CVE-2024-28753 is considered a high severity vulnerability due to its ability to expose sensitive information.
2
How can I fix CVE-2024-28753?
To fix CVE-2024-28753, upgrade RaspAP raspap-webgui to version 3.0.9 or later.
3
What are the potential impacts of CVE-2024-28753?
The potential impacts of CVE-2024-28753 include unauthorized access to the /etc/passwd file, which may lead to account compromise.
4
Who is affected by CVE-2024-28753?
CVE-2024-28753 affects users of RaspAP raspap-webgui versions prior to 3.0.9.
5
Can CVE-2024-28753 be exploited remotely?
Yes, CVE-2024-28753 can be exploited remotely by attackers to read sensitive files.