CVE-2024-7729: CAYIN Technology CMS - Sensitive File Download
Published Aug 14, 2024
·Updated
The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CGI files.
Affected Software
1 affected component
CAYIN Technology CMS
Remediation
Information
Install patch P24012 or later for following versions:
SMP-2100 v3.0
SMP-2200 v3.0
SMP-2210 v3.0
SMP-2300 v3.0
SMP-2310 v3.0
SMP-6000 v3.0
SMP-8000 v3.0
SMP-8000QD v3.0
Install patch P24006 or later for following versions:
CMS-20 v11.0
CMS-60 v11.0
CMS-SE v11.0
CMS-SE(18.04) v11.0
Install patch P24007 or later for following versions:
CMS-SE(22.04) v11.0
Install patch P24008 or later for following versions:
SMP-2200 v4.0
SMP-2210 v4.0
SMP-2300 v4.0
SMP-2310 v4.0
SMP-8100 v4.0
Install patch P24009 or later for following versions:
SMP-2400 v4.0
Event History
Aug 14, 2024
CVE Published
via MITRE·03:52 AM
Data Sourced
via MITRE·03:52 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7729?
CVE-2024-7729 has a critical severity level due to its capability to allow unauthenticated remote attackers to exploit the vulnerability.
2
How do I fix CVE-2024-7729?
To fix CVE-2024-7729, ensure that access controls are properly implemented within the CAYIN Technology CMS.
3
What type of attack is related to CVE-2024-7729?
CVE-2024-7729 is linked to unauthorized file access, allowing attackers to download sensitive CGI files.
4
What versions of CAYIN Technology CMS are affected by CVE-2024-7729?
All versions of CAYIN Technology CMS are affected by CVE-2024-7729 due to lack of proper access control.
5
Who is the vendor for CVE-2024-7729?
The vendor responsible for the affected software in CVE-2024-7729 is CAYIN Technology.