{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-26260","assignerOrgId":"cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e","state":"PUBLISHED","assignerShortName":"twcert","dateReserved":"2024-02-15T01:33:48.679Z","datePublished":"2024-02-15T02:18:34.668Z","dateUpdated":"2024-08-21T15:28:01.013Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","modules":["OAKlouds-organization-2.0","OAKlouds-organization-3.0"],"product":"OAKlouds","vendor":"Hgiga","versions":[{"lessThan":"188","status":"affected","version":"earlier","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["OAKlouds-webbase-2.0","OAKlouds-webbase-3.0"],"product":"OAKlouds","vendor":"Hgiga","versions":[{"lessThan":"1051","status":"affected","version":"earlier","versionType":"custom"}]}],"datePublic":"2024-02-15T02:17:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission."}],"value":"The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission."}],"impacts":[{"capecId":"CAPEC-88","descriptions":[{"lang":"en","value":"CAPEC-88 OS Command Injection"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-78","description":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e","shortName":"twcert","dateUpdated":"2024-06-28T02:06:33.958Z"},"references":[{"tags":["third-party-advisory"],"url":"https://www.twcert.org.tw/tw/cp-132-7673-688b7-1.html"},{"tags":["third-party-advisory"],"url":"https://www.chtsecurity.com/news/e456f679-9091-4de4-8f78-9262d20d6a96"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Update OAKlouds-organization-2.0 to 188 or later version <br>Update OAKlouds-organization-3.0 to 188 or later version <br>Update OAKlouds-webbase-2.0 to 1051 or later version <br>Update OAKlouds-webbase-3.0 to 1051 or later version"}],"value":"Update OAKlouds-organization-2.0 to 188 or later version \nUpdate OAKlouds-organization-3.0 to 188 or later version \nUpdate OAKlouds-webbase-2.0 to 1051 or later version \nUpdate OAKlouds-webbase-3.0 to 1051 or later version"}],"source":{"advisory":"TVN-202402002","discovery":"EXTERNAL"},"title":"Hgiga OAKlouds - Command Injection","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T00:07:17.865Z"},"title":"CVE Program Container","references":[{"tags":["third-party-advisory","x_transferred"],"url":"https://www.twcert.org.tw/tw/cp-132-7673-688b7-1.html"},{"tags":["third-party-advisory","x_transferred"],"url":"https://www.chtsecurity.com/news/e456f679-9091-4de4-8f78-9262d20d6a96"}]},{"affected":[{"vendor":"hgiga","product":"oaklouds","cpes":["cpe:2.3:a:hgiga:oaklouds:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"188","versionType":"custom"},{"version":"0","status":"affected","lessThan":"1051","versionType":"custom"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-08-21T15:11:15.243128Z","id":"CVE-2024-26260","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-08-21T15:28:01.013Z"}}]}}