FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker to execute arbitrary OS commands when certain conditions are met in an environment where the notification program setting is enabled and the executable file path is set to a batch file (.bat) or command file (.cmd) extension.
References
Configurations
No configuration.
History
21 Nov 2024, 09:31
Type | Values Removed | Values Added |
---|---|---|
References | () https://jvn.jp/en/jp/JVN26734798/ - | |
References | () https://www.ffri.jp/assets/files/other_docs/20240729.pdf - | |
References | () https://www.skyseaclientview.net/news/240729_01/ - | |
References | () https://www.support.nec.co.jp/View.aspx?id=3140109694 - |
01 Aug 2024, 13:58
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.4 |
CWE | CWE-78 |
30 Jul 2024, 13:32
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
30 Jul 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-30 09:15
Updated : 2024-11-21 09:31
NVD link : CVE-2024-40895
Mitre link : CVE-2024-40895
CVE.ORG link : CVE-2024-40895
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')