CVE-2024-2413
Estado: AnalizadaCrítica (9.8)—
Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string composed of the user's name and timestamp to generate an authentication code. With this authentication code, they can obtain administrator privileges and subsequently execute arbitrary code on the remote server using built-in system functionality.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.57%
- Percentil entre todas las CVEs puntuadas: 46
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-321
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-2413",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-2413",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-03-13T14:27:09.797092Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "twcert@cert.org.tw",
"affectedData": [
{
"vendor": "Intumit",
"product": "SmartRobot",
"versions": [
{
"status": "affected",
"version": "earlier version",
"versionType": "custom",
"lessThanOrEqual": "v6.1.2-202212tw"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:h:intumit:smartrobot:-:*:*:*:*:*:*:*"
],
"vendor": "intumit",
"product": "smartrobot",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "v6.1.2-202212tw",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-03-13T03:15:06.793",
"references": [
{
"url": "https://www.twcert.org.tw/tw/cp-132-7697-ecf10-1.html",
"tags": [
"Third Party Advisory"
],
"source": "twcert@cert.org.tw"
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-7697-ecf10-1.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"description": [
{
"lang": "en",
"value": "CWE-321"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string composed of the user's name and timestamp to generate an authentication code. With this authentication code, they can obtain administrator privileges and subsequently execute arbitrary code on the remote server using built-in system functionality."
},
{
"lang": "es",
"value": "Intumit SmartRobot utiliza una clave de cifrado fija para la autenticación. Los atacantes remotos pueden usar esta clave para cifrar una cadena compuesta por el nombre del usuario y la marca de tiempo para generar un código de autenticación. Con este código de autenticación, pueden obtener privilegios de administrador y posteriormente ejecutar código arbitrario en el servidor remoto utilizando la funcionalidad integrada del sistema."
}
],
"lastModified": "2026-06-17T07:24:29.237",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:intumit:smartrobot:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89A3232B-BD06-4133-BADF-5725F4E32CA2",
"versionEndExcluding": "6.2.0-202303TW"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "twcert@cert.org.tw"
}