CVE-2024-44599

8.3

FNT · Command

FNT Command 13.4.0 contains a directory traversal vulnerability that allows attackers to access or manipulate files outside of the intended directory structure.

Executive summary

A directory traversal vulnerability in FNT Command 13.4.0 poses a significant risk of unauthorized file system access and system compromise.

Vulnerability

The application is affected by a directory traversal flaw, which allows a low privileged, authenticated attacker to traverse the file system, leading to potential unauthorized file access, modification, or system instability.

Business impact

The ability to perform directory traversal can lead to the exposure of sensitive configuration files, system credentials, or the modification of critical application data. Given the CVSS score of 8.3, this flaw is categorized as High severity, as it facilitates significant unauthorized actions that could lead to full system compromise or service disruption.

Remediation

Immediate Action: Contact FNT support to obtain the latest security patches or configuration hardening guides specific to version 13.4.0.

Proactive Monitoring: Review web server and application access logs for unusual patterns, such as sequences containing directory traversal indicators like dot-dot-slash strings.

Compensating Controls: Implement Web Application Firewall (WAF) rules designed to detect and block path traversal attempts targeted at the FNT Command interface.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists, attributed to the research write-up hosted on GitHub.

Analyst recommendation

This vulnerability presents a serious risk due to the potential for unauthorized file system interaction. Administrators should prioritize identifying instances of FNT Command 13.4.0 within their environment and coordinate with the vendor to apply necessary updates or mitigations immediately to prevent potential exploitation.

More FNT CVEs

Sources