CRITICAL

CVE-2024-7399

Samsung Magicinfo 9 Server 2024-08-12 CVSS v3.1
CVSS
9.8
KEV

Description

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

Summary dbcve.org

A path traversal vulnerability in Samsung MagicINFO 9 Server versions prior to 21.1050 allows unauthenticated attackers to write arbitrary files to the file system with system-level privileges due to insufficient input validation on file path parameters.

Mitigation

Upgrade Samsung MagicINFO 9 Server to version 21.1050 or later. If immediate patching is not possible, restrict write access to the application directories and implement network segmentation to limit exposure.

Weakness (CWE)

CWE-22 Path Traversal
CWE-434 Unrestricted File Upload

EPSS Score

91.94%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE