CRITICAL🇵🇱 Wersja polska

CVE-2024-37770

CVSS 9.1v3.1pub. 2024-07-10upd. 2025-07-01

14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.

🤖 AI Analysis
How it works

The vulnerability is classified as CWE-94 (improper control of code generation) and affects the fingerprint function in the 14Finger application. An attacker can submit a specially crafted payload that is improperly processed by this function, resulting in execution of injected commands in the context of the application. The lack of authentication requirements and low attack complexity (AC:L, PR:N) make this vulnerability exceptionally easy to exploit.

Impact

An attacker can gain full control over the system by executing arbitrary commands — leading to disclosure of sensitive data and modification or deletion of system resources.

Mitigation & patch

Apply patches available from the vendor according to references. It is recommended to monitor the project repository at https://github.com/b1ackc4t/14Finger for updates. Until a patch is released, consider restricting network access to the application.

Who is affected

B1Ackc4T 14Finger version 1.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • B1ackc4t 14finger

    APP
    B1Ackc4T
    1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-37768CRITICAL9.1PL ✓same product

Nieautoryzowane usuwanie użytkowników w 14Finger v1.1

CVE-2024-37767HIGH7.5same product

Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user inf...

CVE-2024-37769HIGH8.8same product

Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator...