CVE-2024-5672: Red Lion Europe: mbNET.mini vulnerable to OS command injection
Published Jul 3, 2024
·Updated
A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.
Affected Software
1 affected component
Red Lion mbNET.mini
Event History
Jul 3, 2024
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-5672?
CVE-2024-5672 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-5672?
To mitigate CVE-2024-5672, ensure that you update the Red Lion mbNET.mini to the latest available version and apply all security patches.
3
Who is affected by CVE-2024-5672?
CVE-2024-5672 affects users of the Red Lion mbNET.mini product.
4
What type of attacks are possible with CVE-2024-5672?
CVE-2024-5672 allows a high privileged remote attacker to execute arbitrary system commands via GET requests.
5
What is the cause of CVE-2024-5672?
CVE-2024-5672 is caused by improper neutralization of special elements used in operating system commands.