CVE-2024-11946

CVSS 3.0 Score 3.1 of 10 (low)

Details

Published Dec 30, 2024
CWE ID 319

Summary

CVE-2024-11946 is a vulnerability affecting iXsystems TrueNAS CORE that allows network-adjacent attackers to tamper with firmware update files without requiring authentication. The issue arises due to the insecure transmission of sensitive information during the update process. Attackers can exploit this flaw, in conjunction with other vulnerabilities, to execute arbitrary code with root privileges. This vulnerability, also known as ZDI-CAN-25668, creates a significant risk for iXsystems TrueNAS devices and highlights the importance of maintaining secure update protocols.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share