CVE-2024-7399: Samsung MagicINFO 9 Server Path Traversal Vulnerability
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
Other sources
Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Samsung MagicINFO 9 Serverto a version that resolves this vulnerability.Fixed in 21.1050 - Compensating control
Discontinue use of Samsung MagicINFO 9 Server if mitigations are unavailable.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7399?
CVE-2024-7399 is classified as a high severity vulnerability due to the potential for attackers to write arbitrary files with system authority.
How do I fix CVE-2024-7399?
To fix CVE-2024-7399, upgrade to Samsung MagicINFO 9 Server version 21.1050 or later.
What are the potential impacts of CVE-2024-7399?
The potential impacts of CVE-2024-7399 include unauthorized access to sensitive files and complete system compromise.
Who is affected by CVE-2024-7399?
Organizations using Samsung MagicINFO 9 Server versions prior to 21.1050 are affected by CVE-2024-7399.
Is there a workaround for CVE-2024-7399?
There is currently no official workaround for CVE-2024-7399; the best course of action is to apply the recommended upgrade.