Security Advisory

CVE-2024-28135

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-05-14 08:09:39
Last updated 2025-01-24 06:35:03
Assigner CERTVDE
CVSS score 5.0
State PUBLISHED

Description

A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.