PT-2024-38516 · Unknown · Threatsonar Anti-Ransomware

CVE-2024-7694

·

Published

2024-08-11

·

Updated

2026-07-03

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ThreatSonar Anti-Ransomware (affected versions not specified)
Description ThreatSonar Anti-Ransomware fails to properly validate the content of uploaded files. Remote attackers with administrator privileges can upload malicious files to execute arbitrary system commands on the server. This flaw has been linked to targeted supply-chain intrusions against high-profile customers in Taiwan, the US, and Japan, attributed to Chinese APT clusters Slime57 and Slime62.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict file upload capabilities to essential, non-executable formats such as text or PDFs by configuring settings to block binary files, scripts, or compressed archives. Implement a multi-layered validation process including both server-side and client-side checks to ensure uploaded files match expected types and sizes. Apply network segmentation and strict access controls to limit the potential impact of an exploit.

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14212
CVE-2024-7694

Affected Products

Threatsonar Anti-Ransomware