IM
IronMonkey Threat Research

CVE-2024-8531 HIGH

Published: 2024-10-11 | Last Modified: 2026-04-15 | Status: Deferred

Description

CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary bash scripts that are executed as root.

Additional Descriptions (1)

CWE-347: Existe una vulnerabilidad de verificación incorrecta de la firma criptográfica que podría comprometer el software Data Center Expert cuando se manipula un paquete de actualización para incluir scripts bash arbitrarios que se ejecutan como root.

CVSS Metrics

Base Score: 7.2 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 1.2

Impact Score: 5.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-347
Notification
Message here