CVE Published: 15/01/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: INCIBE |
Vendor: FireEye |
Product: FireEye Central Management Status : PUBLISHED
CVE-2024-0315 Description
Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704. This vulnerability allows an attacker to upload a malicious PDF file to the system during the report creation process.
Metrics
CVSS Version: 3.1 |
Base Score: 6.6 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CWE-ID: CWE-98 CWE Name: CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program (
PHP Remote File Inclusion
) Source: FireEye
Common Attack Pattern Enumeration and Classification (CAPEC)