CVE-2024-23961

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Sep 28, 2024
Updated: Oct 3, 2024
CWE ID 78

Summary

CVE-2024-23961 is a remote code execution vulnerability affecting Alpine Halo9 devices. The issue lies in the UPDM_wemCmdUpdFSpeDecomp function, which lacks proper validation of user-supplied strings before executing system calls. Consequently, physically present attackers can inject malicious code, executing it with root privileges, without requiring authentication. (Previously identified as ZDI-CAN-23306)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share