8.8
CVSSv3

CVE-2024-22899

Published: 02/02/2024 Updated: 07/02/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Vinchin Backup & Recovery v7.2 exists to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vinchin vinchin backup and recovery

Exploits

Vinchin Backup and Recovery versions 72 and below suffer from a command injection vulnerability in the syncNtpTime function ...

Github Repositories

Comprehensive Exploit Chain for Multiple Vulnerabilities in VinChin Backup & Recovery <= 7.2

CVE-2024-22899-to-22903-ExploitChain πŸ› οΈπŸ”“ This repository houses a full exploit chain for Authenticated Remote Code Execution (RCE) on VinChin version 72 and earlier, addressing vulnerabilities CVE-2024-22899 through CVE-2024-22903 Usage πŸš€ To use the exploit script, execute: $ python exploitpy --help Options πŸ“‹ -h, --help -