CVE-2024-45252

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 6, 2024
Updated: Oct 7, 2024
CWE ID 78

Summary

CVE-2024-45252 is a newly identified cybersecurity vulnerability that affects Elsight's software. This issue is classified as an OS Command Injection (CWE-78), where malicious code is injected into operating system commands, potentially allowing unauthorized access or system compromise. The exact nature of the vulnerability lies in Elsight's software's failure to properly neutralize special elements in OS commands, making it an attractive target for attackers. Successful exploitation of this vulnerability could lead to significant data breaches or unauthorized control of affected systems. Users are urged to apply the necessary patches or updates as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share