Vulnerability Description
reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmap_cmd parameter with malicious base64-encoded payloads to achieve remote code execution during scan engine configuration.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yogeshojha | Rengine | 2.2.0 |
Related Weaknesses (CWE)
References
- https://github.com/yogeshojha/rengineProduct
- https://rengine.wiki/Product
- https://www.exploit-db.com/exploits/52081ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/rengine-authenticated-command-injection-viaThird Party Advisory
FAQ
What is CVE-2024-58287?
CVE-2024-58287 is a vulnerability with a CVSS score of 8.8 (HIGH). reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify ...
How severe is CVE-2024-58287?
CVE-2024-58287 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-58287?
Check the references section above for vendor advisories and patch information. Affected products include: Yogeshojha Rengine.