CVE-2024-7120

Scores

EPSS

0.891high89.1%
0%20%40%60%80%100%

Percentile: 89.1%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
6.5

Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Description

A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file list_base_config.php of the component Web Interface. The manipulation of the argument template leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272451.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-78

Related Vulnerabilities

Exploits

Exploit ID: CVE-2024-7120

Source: github-poc

URL: https://github.com/jokeir07x/CVE-2024-7120-Exploit-by-Dark-07x

Vulnerable Software (4)

Type: Configuration

Vendor: raisecom

Product: msg1200_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:raisecom:msg1200_firmware:3.90:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator":...

Source: nvd

Type: Configuration

Vendor: raisecom

Product: msg2100e_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:raisecom:msg2100e_firmware:3.90:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator"...

Source: nvd

Type: Configuration

Vendor: raisecom

Product: msg2200_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:raisecom:msg2200_firmware:3.90:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator":...

Source: nvd

Type: Configuration

Vendor: raisecom

Product: msg2300_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:raisecom:msg2300_firmware:3.90:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator":...

Source: nvd