« Volver al listado

CVE-2024-7728

Estado: AplazadaAlta (7.2)—

The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and execute them on the remote server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-7728",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-7728",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-14T13:21:24.823282Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "twcert@cert.org.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "twcert@cert.org.tw",
      "affectedData": [
        {
          "vendor": "CAYIN Technology",
          "product": "CMS-SE(22.04)",
          "versions": [
            {
              "status": "affected",
              "version": "11.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "CAYIN Technology",
          "product": "CMS-SE(18.04)",
          "versions": [
            {
              "status": "affected",
              "version": "11.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "CAYIN Technology",
          "product": "CMS-SE",
          "versions": [
            {
              "status": "affected",
              "version": "11.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:cayintech:cms-se\\(22.04\\):11.0:*:*:*:*:*:*:*"
          ],
          "vendor": "cayintech",
          "product": "cms-se\\(22.04\\)",
          "versions": [
            {
              "status": "affected",
              "version": "11.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:cayintech:cms-se\\(18.04\\):11.0:*:*:*:*:*:*:*"
          ],
          "vendor": "cayintech",
          "product": "cms-se\\(18.04\\)",
          "versions": [
            {
              "status": "affected",
              "version": "11.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:cayintech:cms-se:11.0:*:*:*:*:*:*:*"
          ],
          "vendor": "cayintech",
          "product": "cms-se",
          "versions": [
            {
              "status": "affected",
              "version": "11.0"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-08-14T04:15:06.757",
  "references": [
    {
      "url": "https://resource1.cayintech.com/patch/",
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/en/cp-139-8002-b6167-2.html",
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-8001-8416d-1.html",
      "source": "twcert@cert.org.tw"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "twcert@cert.org.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and execute them on the remote server."
    },
    {
      "lang": "es",
      "value": "El CGI específico del CMS de CAYIN Technology no valida adecuadamente la entrada del usuario, lo que permite a un atacante remoto con privilegios de administrador inyectar comandos del sistema operativo en el parámetro específico y ejecutarlos en el servidor remoto."
    }
  ],
  "lastModified": "2026-06-17T08:20:48.103",
  "sourceIdentifier": "twcert@cert.org.tw"
}