CVE-2024-13129

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 3, 2025
CWE ID 78
CWE ID 77

Summary

CVE-2024-13129 is a critical vulnerability affecting Roxy-WI versions up to 8.1.3. The function action_service in the file app/modules/roxywi/roxy.py is the source of the issue. An attacker can manipulate the argument action/service to inject os commands, enabling remote exploitation. The vulnerability has been publicly disclosed, increasing the risk. Upgrading to version 8.1.4, with patch identifier 32313928eb9ce906887b8a30bf7b9a3d5c0de1be, resolves this issue. It is strongly advised to upgrade the affected component promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share