CVE-2024-23749
KiTTY 0.76.1.13 - Command Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
-Decision
Descriptions
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls (at lines 2369-2390). This allows an attacker to add inputs inside the filename variable, leading to arbitrary code execution.
Las versiones de KiTTY 0.76.1.13 y anteriores son vulnerables a la inyección de comandos a través de la variable de nombre de archivo, se produce debido a una sanitización y validación de entrada insuficientes, no se pueden escapar caracteres especiales y llamadas inseguras al sistema (en las líneas 2369-2390). Esto permite a un atacante agregar entradas dentro de la variable de nombre de archivo, lo que lleva a la ejecución de código arbitrario.
KiTTY versions 0.76.1.13 and below suffer from a command injection vulnerability when getting a remote file through scp. It appears to leverage an ANSI escape sequence issue which is quite an interesting vector of attack.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-01-21 CVE Reserved
- 2024-02-08 CVE Published
- 2024-03-14 First Exploit
- 2024-08-01 CVE Updated
- 2024-09-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/51892 | 2024-03-14 | |
http://packetstormsecurity.com/files/177031/KiTTY-0.76.1.13-Command-Injection.html | 2024-08-01 | |
http://seclists.org/fulldisclosure/2024/Feb/13 | 2024-08-01 | |
http://seclists.org/fulldisclosure/2024/Feb/14 | 2024-08-01 | |
https://blog.defcesco.io/CVE-2024-23749 | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
9bis Search vendor "9bis" | Kitty Search vendor "9bis" for product "Kitty" | <= 0.76.1.13 Search vendor "9bis" for product "Kitty" and version " <= 0.76.1.13" | windows |
Affected
|