CVE-2024-55544: Authenticated Command Injection
Published Dec 10, 2024
·Updated
Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below.
Affected Software
3 affected components
ORing IAP-420<2.01e
All of the following
Oringnet Iap-420 Firmware<=2.01e
Oringnet Iap-420
Event History
Dec 10, 2024
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55544?
CVE-2024-55544 is classified as a medium severity vulnerability due to its potential for stored Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2024-55544?
To fix CVE-2024-55544, you should upgrade the ORing IAP-420 to a version above 2.01e.
3
What versions of ORing IAP-420 are affected by CVE-2024-55544?
CVE-2024-55544 affects ORing IAP-420 version 2.01e and below.
4
What type of vulnerability is CVE-2024-55544?
CVE-2024-55544 is a stored Cross-Site Scripting (XSS) vulnerability due to missing input validation.
5
Can CVE-2024-55544 be exploited remotely?
Yes, CVE-2024-55544 can be exploited remotely via the web interface of the affected device.