Update CVE-2024-23692
parent
e322f31421
commit
f3bcd3e920
|
@ -1,10 +1,19 @@
|
||||||
id: CVE-2024-23692
|
id: CVE-2024-23692
|
||||||
|
|
||||||
info:
|
info:
|
||||||
name: HFS Command Injection RCE
|
name: Check Point Quantum Gateway - Information Disclosure
|
||||||
author: johnk3r
|
author: johnk3r
|
||||||
severity: critical
|
severity: high
|
||||||
tags: rce,hfs,cve
|
description: |
|
||||||
|
CVE-2024-24919 is an information disclosure vulnerability that can allow an attacker to access certain information on internet-connected Gateways which have been configured with IPSec VPN, remote access VPN, or mobile access software blade.
|
||||||
|
reference:
|
||||||
|
- https://github.com/rapid7/metasploit-framework/pull/19240
|
||||||
|
- https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/
|
||||||
|
metadata:
|
||||||
|
verified: true
|
||||||
|
max-request: 1
|
||||||
|
shodan-query: product:"HttpFileServer httpd"
|
||||||
|
tags: cve,cve2024,hfs,rce
|
||||||
|
|
||||||
requests:
|
requests:
|
||||||
- method: GET
|
- method: GET
|
||||||
|
|
Loading…
Reference in New Issue