CVE-2024-41789: OS Command Injection
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the language parameter in specific POST requests. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41789?
CVE-2024-41789 is considered a critical vulnerability due to its potential for remote code execution with root privileges.
How do I fix CVE-2024-41789?
To mitigate CVE-2024-41789, update the SENTRON 7KT PAC1260 Data Manager to the latest version with patched software.
Who is affected by CVE-2024-41789?
All versions of the Siemens SENTRON 7KT PAC1260 Data Manager are affected by CVE-2024-41789.
What type of attacks can exploit CVE-2024-41789?
CVE-2024-41789 can be exploited by an authenticated remote attacker to execute arbitrary code on the device.
What is the nature of the vulnerability in CVE-2024-41789?
The vulnerability in CVE-2024-41789 arises from improper sanitization of the language parameter in specific POST requests.