The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published an advisory to warn of a vulnerability, tracked as\u00a0CVE-2024-7029<\/a> (CVSS base score of 8.8), in Avtech camera that has been exploited in the wild.\u00a0<\/p>\n\n\n\n
“Successful exploitation of this vulnerability could allow an attacker to inject and execute commands as the owner of the running process.” reads the advisory<\/strong><\/a> published by CISA.<\/em> “Commands can be injected over the network and executed without authentication.”<\/em><\/p>\n\n\n\n
CISA attempted to report the issue to the vendor that has yet to respond to requests.<\/p>\n\n\n\n
The US Agency advises users to reduce the risk of exploitation of the vulnerability CVE-2024-7029<\/a> by:<\/p>\n\n\n\n
Multiple botnets are known to target Avtech devices, including Mirai<\/a>, Death botnet<\/a>, Hide \u2018N Seek<\/a>\u00a0and\u00a0HNS<\/a>.
Follow me on Twitter: @securityaffairs<\/strong><\/a> and Facebook<\/strong><\/a> and Mastodon<\/strong><\/a><\/p>\n\n\n\n
Pierluigi Paganini<\/strong><\/a><\/p>\n\n\n\n
(<\/strong>SecurityAffairs<\/strong><\/a>\u00a0\u2013<\/strong>\u00a0hacking, CISA)<\/strong><\/p>\n\n\n\n