← Retour aux CVEs
CVE-2024-7694
HIGHCISA KEV7.2
Description
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
Details CVE
Score CVSS v3.17.2
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie8/12/2024
Derniere modification2/18/2026
Sourcekev
Observations honeypot0
CISA KEV
FournisseurTeamT5
ProduitThreatSonar Anti-Ransomware
Nom vulnerabiliteTeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
Date ajout KEV2026-02-17
Date limite remediation2026-03-10
Utilise dans ransomwareUnknown
Produits affectes
teamt5:threatsonar_anti-ransomware
Faiblesses (CWE)
CWE-434
References
https://www.twcert.org.tw/en/cp-139-8000-e5a5c-2.html(twcert@cert.org.tw)
https://www.twcert.org.tw/tw/cp-132-7998-d76dd-1.html(twcert@cert.org.tw)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7694(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.