Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33224 | IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on the server. |
Solution
Update to version 2.8.1.240731 or late, and it is recommended to enable the 'Connection IP Whitelist' feature on the administrator interface to reduce the risk of attack.
Workaround
No workaround given by the vendor.
Mon, 04 Nov 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 01 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Changingtec
Changingtec idexpert |
|
| CPEs | cpe:2.3:a:changingtec:idexpert:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Changingtec
Changingtec idexpert |
|
| Metrics |
ssvc
|
Fri, 01 Nov 2024 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on the server. | |
| Title | CHANGING Information Technology IDExpert - OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-11-04T06:47:22.301Z
Reserved: 2024-11-01T02:36:02.585Z
Link: CVE-2024-10653
Updated: 2024-11-01T13:30:47.007Z
Status : Awaiting Analysis
Published: 2024-11-01T10:15:05.103
Modified: 2024-11-04T07:15:03.743
Link: CVE-2024-10653
No data.
OpenCVE Enrichment
No data.
EUVD