Our takeCISA flags an OS command injection in ZoneMinder (versions 1.37.48 and 1.38.3) — CVSS 8.8, full RCE as the web server user. This open-source camera software runs in plenty of small shops: update, and if your web interface is reachable from the internet, fix that today.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:CISA reports active exploitation of an OS command injection in ZoneMinder 1.37.48 and 1.38.3 (CVSS 8.8) that yields full RCE as the web server user. Update immediately and place the web interface behind authentication and network controls.
What this means for you — Lean IT orgs:ZoneMinder versions 1.37.48 and 1.38.3 have a serious remote code execution flaw that CISA says is being exploited. Update to a fixed version right away and do not expose the web interface to the internet.
What this means for you — MSP:CISA reports active exploitation of an OS command injection (CVSS 8.8) in ZoneMinder 1.37.48 and 1.38.3 that gives full RCE as the web server user. Check every client running this software, update now, and confirm the web interface is not reachable from the internet.
What this means for you — Researcher:CISA reports active exploitation of an OS command injection in ZoneMinder 1.37.48 and 1.38.3 (CVSS 8.8) resulting in full RCE as the web server user.