CVE-2024-41788: OS Command Injection
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the input parameters in specific GET requests. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41788?
CVE-2024-41788 is considered a high-severity vulnerability due to its potential for authenticated remote code execution with root privileges.
How do I fix CVE-2024-41788?
To fix CVE-2024-41788, ensure that you apply the latest security patches provided by Siemens for the SENTRON 7KT PAC1260 Data Manager.
Who is affected by CVE-2024-41788?
CVE-2024-41788 affects all versions of the SENTRON 7KT PAC1260 Data Manager.
What type of attack does CVE-2024-41788 allow?
CVE-2024-41788 allows an authenticated remote attacker to execute arbitrary code on the affected device.
How can I determine if my device is vulnerable to CVE-2024-41788?
You can determine if your device is vulnerable by checking if it runs the SENTRON 7KT PAC1260 Data Manager and has not been updated with the latest security patches.