Podatność CVE-2024-22900


Publikacja: 2024-02-02

Opis:
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.

W naszej bazie, znaleźliśmy następujące noty dla tego CVE:
Tytuł
Autor
Data
Med.
Vinchin Backup And Recovery 7.2 setNetworkCardInfo Command Injection
Valentin Lobstei...
26.01.2024

Typ:

CWE-78

(Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') )

 Referencje:
http://vinchin.com
https://seclists.org/fulldisclosure/2024/Jan/29
https://blog.leakix.net/2024/01/vinchin-backup-rce-chain/

Copyright 2024, cxsecurity.com

 

Back to Top