CVE-2024-7442
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Aug 3, 2024
Updated: Aug 6, 2024
CWE ID 77
Summary
CVE-2024-7442 is a critical vulnerability affecting the Vivotek SD9364 VVTK-0103f model. The issue lies in the getenv function of the file upload_file.cgi, which can be exploited through manipulation of the QUERY_STRING argument. This command injection vulnerability can be exploited remotely. The associated identifier for this vulnerability is VDB-273527. Notably, this vulnerability affects only unsupported product versions and has been confirmed end-of-life by the vendor.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.