S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Sep 24, 2024

CVE-2024-5421 Scanner

CVE-2024-5421 scanner - Arbitrary File Disclosure vulnerability in SEH utnserver Pro/ProMAX/INU-100

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-5421
8.7
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
utnserver Proby SEH Computertechnik
0
utnserver ProMAXby SEH Computertechnik
0
INU-100by SEH Computertechnik
0
utnserver_proby seh
0
Updated Sep 10, 2026View on NVD →
Detail

The SEH utnserver Pro/ProMAX/INU-100 is utilized in various industrial applications to manage and expose data services. Developed for secure file handling, it supports authenticated access to various files and directories. However, due to vulnerabilities, sensitive information can be improperly accessed. Organizations depend on it for reliable data management, but must ensure security. Regular vulnerability checks are crucial for maintaining integrity and confidentiality.

The identified vulnerability allows for arbitrary file disclosure within the SEH utnserver Pro/ProMAX/INU-100. This flaw permits authenticated users to access sensitive files that should be protected. While authentication is required, the vulnerability poses a significant risk of data exposure. It has been publicly disclosed as CVE-2024-5421, highlighting the importance of prompt remediation.

This vulnerability is found in the file handling functions of the SEH utnserver Pro, utnserver ProMAX, and INU-100. Specifically, it is triggered by unauthorized access attempts to the /info/dir?/ endpoint. The vulnerability arises when the server improperly processes requests, allowing sensitive information leakage. The presence of indicators in the response body signifies potential exposure of file system information. As a result, even authenticated users may retrieve data that could compromise security.

If exploited, this vulnerability can lead to significant data exposure, allowing unauthorized access to sensitive files. Malicious users could leverage this access for various nefarious purposes, including data theft and system compromise. Such breaches could result in reputational damage and financial loss for organizations. Additionally, it may violate compliance requirements and lead to legal repercussions.

By becoming a member of the S4E platform, you gain access to advanced vulnerability detection tools tailored to protect your digital assets. Our platform not only identifies vulnerabilities but also provides actionable remediation strategies. You’ll benefit from continuous monitoring, ensuring your systems are secure against evolving threats. Join us to enhance your cybersecurity posture and safeguard your valuable data.

References:

Solution Advice
  • Regularly update to the latest version of SEH utnserver Pro/ProMAX/INU-100.
  • Implement strict access controls to limit authenticated users.
  • Regularly audit and monitor file access logs for suspicious activity.
  • Employ additional security measures, such as web application firewalls.
  • Conduct routine vulnerability assessments to identify potential weaknesses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-5421 scanner - Arbitrary File Disclosure vulnerability in SEH utnserver Pro/ProMAX/INU-100 | S4E