CVE-2024-7694 is a critical arbitrary command execution vulnerability affecting TeamT5 ThreatSonar Anti-Ransomware, stemming from improper file upload validation. With a CVSS score of 7.2 (HIGH), this flaw allows remote attackers with administrator privileges to upload malicious files, leading to full compromise of the server. This vulnerability is actively exploited (KEV listed) and has garnered significant community discussion and media coverage, despite no public exploit code being readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5.0CPE matchmatch criteria | cpe:2.3:a:teamt5:threatsonar_anti-ransomware:*:*:*:*:*:*:*:* | ||
>= 0, <= 3.4.5CPE match | cpe:2.3:a:teamt5:threatsonar_anti-ransomware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.