CVE-2024-46256
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Sep 27, 2024
Updated: Oct 24, 2024
CWE ID 77
Summary
CVE-2024-46256 is a newly disclosed command injection vulnerability that affects the requestLetsEncryptSsl function in NginxProxyManager version 2.11.3. An attacker can exploit this vulnerability by adding a maliciously crafted certificate request, resulting in arbitrary command execution. This issue poses a serious risk, as an attacker can gain unauthorized access, install malware, or perform other malicious actions on the affected system. Users are urged to update to the latest version of NginxProxyManager to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.