CVE-2024-40895: Command Injection
FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker to execute arbitrary OS commands when certain conditions are met in an environment where the notification program setting is enabled and the executable file path is set to a batch file (.bat) or command file (.cmd) extension.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40895?
CVE-2024-40895 is classified with a high severity due to the potential for remote code execution by unauthenticated attackers.
How does CVE-2024-40895 affect FFRI AMC versions 3.4.0 to 3.5.3?
CVE-2024-40895 allows attackers to execute arbitrary OS commands when certain conditions are met in environments where the notification program setting is enabled.
What steps can be taken to mitigate CVE-2024-40895?
Mitigation for CVE-2024-40895 includes disabling the notification program setting or upgrading to a patched version of FFRI AMC.
Is CVE-2024-40895 applicable to OEM products?
Yes, CVE-2024-40895 also affects certain OEM products that implement or bundle FFRI AMC versions 3.4.0 to 3.5.3.
Can CVE-2024-40895 be exploited remotely?
Yes, CVE-2024-40895 can be exploited remotely by unauthenticated attackers given the right conditions.