CVE-2024-8655
CVE-2024-8655: Exposes sensitive files in Mercury MNVR816 devices. A remote file access vulnerability exists in Mercury MNVR816 up to version 2.0.1.0.5, allowing unauthorized access to files and directories via manipulation of the '/web-static/' file path. The exploit is publicly available, increasing the risk of exploitation. With an SVRS of 50, while not critical, this vulnerability still poses a significant risk. Although the CVSS score is 5.3, the public exploit increases the likelihood of attacks. The vendor's lack of response exacerbates the situation. Organizations using this device should implement mitigation measures to prevent unauthorized data access.
Description:
CVE-2024-8655 is a vulnerability in Mercury MNVR816 up to 2.0.1.0.5 that allows remote attackers to access files or directories. The vulnerability has been classified as problematic and is actively exploited in the wild.
Key Insights:
- SVRS Score: 30 (Moderate)
- CVSS Score: 5.3 (Medium)
- Exploit Status: Active exploits have been published
- CISA Warning: The Cybersecurity and Infrastructure Security Agency (CISA) has warned of the vulnerability, calling for immediate and necessary measures
Mitigation Strategies:
- Update to the latest version of Mercury MNVR816 (2.0.1.0.6 or later)
- Restrict access to the affected file (/web-static/)
- Implement file integrity monitoring to detect unauthorized changes
- Regularly scan for vulnerabilities and patch systems promptly
Additional Information:
If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.