CVE-2024-6186
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Jun 20, 2024
CWE ID 78
Summary
CVE-2024-6186 is a critical vulnerability affecting Ruijie RG-UAC 1.0. The issue lies in an unspecified part of the commit.php file located at /view/userAuthentication/SSO/. An attacker can exploit this flaw by manipulating the ad_log_name argument to execute os commands remotely. This vulnerability, identified as VDB-269157, has been publicly disclosed, increasing the risk of exploitation. Despite early notification, the vendor has not responded to disclose a patch or mitigation strategy.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.