Vulnerability Description
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rhubcom | Turbomeeting | < 8.0 |
Related Weaknesses (CWE)
References
- https://github.com/google/security-research/security/advisories/GHSA-gx6g-8mvx-3ExploitThird Party Advisory
- https://www.rhubcom.com/v5/manuals.htmlProduct
- https://github.com/google/security-research/security/advisories/GHSA-gx6g-8mvx-3ExploitThird Party Advisory
- https://www.rhubcom.com/v5/manuals.htmlProduct
FAQ
What is CVE-2024-38288?
CVE-2024-38288 is a vulnerability with a CVSS score of 7.2 (HIGH). A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary com...
How severe is CVE-2024-38288?
CVE-2024-38288 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-38288?
Check the references section above for vendor advisories and patch information. Affected products include: Rhubcom Turbomeeting.