CVE-2024-31977: OS Command Injection
Published Jul 24, 2024
·Updated
Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via shell metacharacters to the Ping or Traceroute utility.
Affected Software
3 affected components
Adtran Sdg Smartos<12.5.5.1
All of the following
Adtran 834-5 Firmware=11.1.0.101-202106231430
Adtran 834-5
Event History
Jul 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31977?
CVE-2024-31977 is classified as a high severity vulnerability due to its potential for OS command injection.
2
How do I fix CVE-2024-31977?
To mitigate CVE-2024-31977, upgrade to SmartOS Version 12.6.3.1 or later for affected devices.
3
What types of devices are affected by CVE-2024-31977?
CVE-2024-31977 affects Adtran 834-5 devices running firmware 11.1.0.101-202106231430 and older versions of SmartOS.
4
What attack vectors are associated with CVE-2024-31977?
CVE-2024-31977 allows attackers to exploit the Ping or Traceroute utility via shell metacharacters.
5
Is there a workaround for CVE-2024-31977?
Currently, the recommended action is to update the software, as no specific workaround is documented for CVE-2024-31977.