CVE-2024-5411: Command Injection
Published May 28, 2024
·Updated
Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e and below.
Affected Software
3 affected components
IAP IAP-420<2.01e
All of the following
Oringnet Iap-420 Firmware<=2.01e
Oringnet Iap-420
Event History
May 28, 2024
CVE Published
via MITRE·10:28 AM
Data Sourced
via MITRE·10:28 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5411?
CVE-2024-5411 is considered a critical vulnerability due to its potential for authenticated command injection.
2
How do I fix CVE-2024-5411?
To mitigate CVE-2024-5411, upgrade the IAP-420 firmware to version 2.02 or newer, which addresses input validation issues.
3
What versions are affected by CVE-2024-5411?
CVE-2024-5411 affects IAP-420 versions 2.01e and below.
4
Who is impacted by CVE-2024-5411?
Users of the IAP-420 web interface running versions 2.01e and older are vulnerable to CVE-2024-5411.
5
What type of vulnerability is CVE-2024-5411?
CVE-2024-5411 is categorized as a command injection vulnerability stemming from missing input validation.