CVE-2024-8779

OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowing remote attackers with regular privileges to update system settings or create accounts with administrator privileges, thereby gaining control of the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:syscomgo:omflow:*:*:*:*:*:*:*:*

History

17 Sep 2024, 11:27

Type Values Removed Values Added
First Time Syscomgo
Syscomgo omflow
CWE CWE-284 NVD-CWE-Other
CPE cpe:2.3:a:syscomgo:omflow:*:*:*:*:*:*:*:*
References () https://www.twcert.org.tw/en/cp-139-8076-6ade0-2.html - () https://www.twcert.org.tw/en/cp-139-8076-6ade0-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-8075-a0d06-1.html - () https://www.twcert.org.tw/tw/cp-132-8075-a0d06-1.html - Third Party Advisory

16 Sep 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-16 06:15

Updated : 2024-09-17 11:27


NVD link : CVE-2024-8779

Mitre link : CVE-2024-8779


JSON object : View

Products Affected

syscomgo

  • omflow