Full Report
Huntress has verified Samsung’s MagicINFO 9 Server (version 21.1050.0) is vulnerable to a publicly available proof-of-concept (PoC). Understand why MagicINFO 9 Server shouldn’t be internet-facing until a patch is applied.
Analysis Summary
# Vulnerability: Samsung MagicINFO 9 Server Unauthenticated Remote Code Execution (RCE)
## CVE Details
- **CVE ID:** CVE-2024-7399
- **CVSS Score:** 9.8 (Critical) – *Note: While the original CVE was scored high/critical, Huntress reports the current patch is ineffective for the latest version.*
- **CWE:** CWE-434 (Unrestricted Upload of File with Dangerous Type) / CWE-287 (Improper Authentication)
## Affected Systems
- **Products:** Samsung MagicINFO 9 Server (Content Management System for digital signage).
- **Versions:** 21.1050.0 (Latest available version) and 21.1040.2.
- **Configurations:** Systems where the MagicINFO web console is exposed to the internet.
## Vulnerability Description
The vulnerability allows an unauthenticated remote attacker to bypass security controls and upload a malicious web shell to the server. Because the application runs via Apache Tomcat, the uploaded shell grants the attacker Remote Code Execution (RCE) under the context of the Tomcat process. While Samsung previously released a patch for CVE-2024-7399 in August 2024, Huntress has verified that the patch is either incomplete or does not cover a secondary, similar flaw, leaving the most recent version of the software vulnerable.
## Exploitation
- **Status:** **Exploited in the wild.** A publicly available Proof-of-Concept (PoC) exists. It is also reportedly being leveraged by a version of the Mirai botnet.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full access to server files and CMS data)
- **Integrity:** High (Ability to modify content, system files, and signage displays)
- **Availability:** High (Potential for ransomware, botnet recruitment, or system shutdown)
## Remediation
### Patches
- **None Currently Effective:** As of May 7, 2025, the latest version (21.1050.0) remains vulnerable. The previous patch released in August 2024 is confirmed to be insufficient.
### Workarounds
- **Network Isolation:** Immediately remove Samsung MagicINFO 9 Server from the public internet.
- **VPN/Access Control:** Restrict access to the management console to internal networks only or via a secure VPN.
- **IP Whitelisting:** If remote access is required, restrict access to known, trusted IP addresses.
## Detection
- **Indicators of Compromise:**
- Presence of unexpected JSP files in the Apache Tomcat webapps directory (web shells).
- Unusual outbound traffic originating from the MagicINFO server (indicative of botnet activity like Mirai).
- Unauthorized configuration changes or new administrative users within the MagicINFO dashboard.
- **Detection Methods:** Monitor web server logs for suspicious POST requests to upload endpoints, particularly those originating from unknown external IPs.
## References
- **SSD Disclosure:** hxxps[://]ssd-disclosure[.]com/ssd-advisory-samsung-magicinfo-unauthenticated-rce/
- **Huntress Research:** hxxps[://]www[.]huntress[.]com/blog/rapid-response-samsung-magicinfo9-server-flaw
- **SANS ISC Report:** hxxps[://]isc[.]sans[.]edu/diary/rss/31920
- **Samsung Security Updates:** hxxps[://]security[.]samsungtv[.]com/securityUpdates