CVE-2024-58287: reNgine 2.2.0 Authenticated Command Injection via Scan Engine Configuration
reNgine 2.2.0 contains a command injection vulnerability in the nmapcmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmapcmd parameter with malicious base64-encoded payloads to achieve remote code execution during scan engine configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58287?
CVE-2024-58287 is classified as a high severity vulnerability due to its capability for authenticated attackers to execute arbitrary commands.
How do I fix CVE-2024-58287?
To fix CVE-2024-58287, apply the latest security patch provided by the reNgine development team for version 2.2.0.
What type of attack is associated with CVE-2024-58287?
CVE-2024-58287 is associated with command injection attacks that exploit improper validation of the nmap_cmd parameter.
Who is affected by CVE-2024-58287?
CVE-2024-58287 affects authenticated users of reNgine version 2.2.0 who can modify the nmap_cmd parameter.
What are the potential impacts of CVE-2024-58287?
The potential impacts of CVE-2024-58287 include unauthorized command execution, leading to data breaches or system compromise.