CRITICAL
CVE-2024-7399
CVSS
9.8
KEV
Description
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
Summary dbcve.org
A path traversal vulnerability in Samsung MagicINFO 9 Server versions prior to 21.1050 allows unauthenticated attackers to write arbitrary files to the file system with system-level privileges due to insufficient input validation on file path parameters.
Mitigation
Upgrade Samsung MagicINFO 9 Server to version 21.1050 or later. If immediate patching is not possible, restrict write access to the application directories and implement network segmentation to limit exposure.
Weakness (CWE)
CWE-22
Path Traversal
CWE-434
Unrestricted File Upload
EPSS Score
91.94%
Probability of exploitation in next 30 days
99.8th percentile
References
https://security.samsungtv.com/securityUpdates
Vendor Advisory
https://arcticwolf.com/resources/blog-uk/arctic-wolf-observes-exploitation-of-path-traversal-vulnerability-in-samsung-magicinfo-9-server-cve-2024-7399/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7399
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.