We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-3785

Improper Neutralization of Server-Side Includes (SSI) vulnerability in WBSAirback



AssignerINCIBE
Reserved2024-04-15
Published2024-04-15
Updated2024-08-01

Description

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device NAS shared section (/admin/DeviceNAS). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.



MEDIUM: 6.6CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Problem types

Improper Neutralization of Server-Side Includes (SSI) Within a Web Page

Product status

Default status
unaffected

21.02.04
affected

Credits

Alejandro Amorín Niño 0x40082c9600

Guillermo Tuvilla Gómez 0x40082c9610

Sergio Román Hurtado 0x40082c9620

References

https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions

cve.org CVE-2024-3785

nvd.nist.gov CVE-2024-3785

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.