PT-2024-38516 · Unknown · Threatsonar Anti-Ransomware
CVE-2024-7694
·
Published
2024-08-11
·
Updated
2026-07-03
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ThreatSonar Anti-Ransomware (affected versions not specified)
Description
ThreatSonar Anti-Ransomware fails to properly validate the content of uploaded files. Remote attackers with administrator privileges can upload malicious files to execute arbitrary system commands on the server. This flaw has been linked to targeted supply-chain intrusions against high-profile customers in Taiwan, the US, and Japan, attributed to Chinese APT clusters Slime57 and Slime62.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict file upload capabilities to essential, non-executable formats such as text or PDFs by configuring settings to block binary files, scripts, or compressed archives.
Implement a multi-layered validation process including both server-side and client-side checks to ensure uploaded files match expected types and sizes.
Apply network segmentation and strict access controls to limit the potential impact of an exploit.
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Threatsonar Anti-Ransomware