CVE-2024-11946
CVE-2024-11946: iXsystems TrueNAS CORE vulnerability allows attackers to tamper with firmware update files. This security flaw arises from the transmission of sensitive information in cleartext during the fetching of plugin packagesites using tar, leading to potential compromise. The SVRS score is 30, indicating a low risk, but the presence of "In The Wild" tag suggests that it is actively exploited. Attackers can exploit this flaw by intercepting and modifying the firmware update process, potentially leading to arbitrary code execution with root privileges when combined with other vulnerabilities. Even though the CVSS is 0, the real-world exploitation risk is notable because authentication is not needed. Organizations using iXsystems TrueNAS CORE should monitor their systems. This vulnerability is significant as it enables malicious actors to gain unauthorized control over the TrueNAS CORE devices.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.