Improper Verification of Cryptographic Signature in Struxureware Data Center Expert - CVE-2024-8531

 

Improper Verification of Cryptographic Signature in Struxureware Data Center Expert - CVE-2024-8531

Published: October 16, 2024 / Updated: October 18, 2024


Vulnerability identifier: #VU98729
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-8531
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the target system.

The vulnerability exists due to improper verification of cryptographic signature. A remote administrator can compromise the target software when an upgrade bundle is manipulated to include arbitrary bash scripts that are executed as root.


Affected software

Struxureware Data Center Expert

How to mitigate CVE-2024-8531

Install updates from vendor's website.

Struxureware Data Center Expert - update to 8.2

External References

Related Security Bulletins