CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-8655

High Severity
SVRS
50/100

CVSSv3
5.3/10

EPSS
0.00058/1

CVE-2024-8655: Exposes sensitive files in Mercury MNVR816 devices. A remote file access vulnerability exists in Mercury MNVR816 up to version 2.0.1.0.5, allowing unauthorized access to files and directories via manipulation of the '/web-static/' file path. The exploit is publicly available, increasing the risk of exploitation. With an SVRS of 50, while not critical, this vulnerability still poses a significant risk. Although the CVSS score is 5.3, the public exploit increases the likelihood of attacks. The vendor's lack of response exacerbates the situation. Organizations using this device should implement mitigation measures to prevent unauthorized data access.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:N
UI:N
S:U
C:L
I:N
A:N
2024-09-10

2024-09-11
Eye Icon
SOCRadar
AI Insight

Description:

CVE-2024-8655 is a vulnerability in Mercury MNVR816 up to 2.0.1.0.5 that allows remote attackers to access files or directories. The vulnerability has been classified as problematic and is actively exploited in the wild.

Key Insights:

  • SVRS Score: 30 (Moderate)
  • CVSS Score: 5.3 (Medium)
  • Exploit Status: Active exploits have been published
  • CISA Warning: The Cybersecurity and Infrastructure Security Agency (CISA) has warned of the vulnerability, calling for immediate and necessary measures

Mitigation Strategies:

  • Update to the latest version of Mercury MNVR816 (2.0.1.0.6 or later)
  • Restrict access to the affected file (/web-static/)
  • Implement file integrity monitoring to detect unauthorized changes
  • Regularly scan for vulnerabilities and patch systems promptly

Additional Information:

If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

No news found for this CVE

Social Media

🚨 CVE-2024-8655: Mercury MNVR816 up to 2.0.1.0.5 vulnerable to file access via /web-static/. Impact: Unauthorized access to files/directories. Action: Apply restrictive firewalling immediately to mitigate risk. #CyberSecurity #Vulnerability
0
0
0

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://vuldb.com/?ctiid.276963
[email protected]https://vuldb.com/?id.276963
[email protected]https://vuldb.com/?submit.401301

CWE Details

CWE IDCWE NameDescription
CWE-552Files or Directories Accessible to External PartiesThe product makes files or directories accessible to unauthorized actors, even though they should not be.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence