CRITICAL🇵🇱 Wersja polska

CVE-2024-10035

CVSS 9.2v4.0pub. 2024-11-04upd. 2026-06-02

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in BG-TEK Informatics Security Technologies CoslatV3 allows Command Injection, Privilege Escalation. This issue affects CoslatV3: through 3.1069. NOTE: The vendor was contacted and it was learned that the product is not supported.

🤖 AI Analysis
How it works

The vulnerability results from improper neutralization of special characters in system commands (OS Command Injection) and improper control of code generation (Code Injection). A local, authenticated user can inject malicious commands or code that will be executed in the operating system context. The vulnerability allows for privilege escalation, which can lead to system takeover.

Impact

An attacker can execute arbitrary system commands and obtain higher privileges, which threatens the confidentiality, integrity, and availability of both the local system and related systems.

Mitigation & patch

The manufacturer confirmed lack of support for the product — an official patch will not be released. It is recommended to immediately discontinue the product or isolate the system from the network and restrict local access to trusted users only until migration to a supported solution.

Who is affected

BG-TEK Informatics Security Technologies CoslatV3 in all versions up to and including 3.1069.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Bg Tek Coslat

    APP
    Bg-Tek
    3.0 – 3.1069
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPECommand Injection
CWE
References

Related vulnerabilities

CVE-2021-4105CRITICAL9.8PL ✓same vendor

RCE przez nieprawidłową obsługę parametrów w BG-TEK COSLAT Firewall