CVE-2024-11946
CVSS 3.0 Score 3.1 of 10 (low)
Details
Summary
CVE-2024-11946 is a vulnerability affecting iXsystems TrueNAS CORE that allows network-adjacent attackers to tamper with firmware update files without requiring authentication. The issue arises due to the insecure transmission of sensitive information during the update process. Attackers can exploit this flaw, in conjunction with other vulnerabilities, to execute arbitrary code with root privileges. This vulnerability, also known as ZDI-CAN-25668, creates a significant risk for iXsystems TrueNAS devices and highlights the importance of maintaining secure update protocols.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.