Vulnary
← back to the feed
Critical· 9.8actively exploited

CVE-2024-23692

Rejetto HTTP File Server up to version 2.3m contains a critical template injection flaw that lets attackers run arbitrary commands on the server. The vulnerability is remote, requires no authentication or user interaction, and is no longer supported by the vendor.

publishedMay 31, 2024
last modifiedAug 11, 2026
sourcesNVD · CISA-KEV
severity · cvss
9.8
critical · how bad it is
exploitation · epss
99%
100th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 25, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Rejetto HTTP File Server version 2.3m and earlier. Administrators who run the server are the typical users.

02

Real-world impact

An attacker can execute any command on the affected system, giving full control over files, processes, and network resources. This could lead to data theft, system compromise, or the server being used for further attacks.

03

Why this severity

The CVSS score of 9.8 reflects that the flaw is exploitable from the network, requires no privileges, and can compromise confidentiality, integrity, and availability of the entire system.

04

What to do about it

no official fix yet
interim mitigations
  • Apply vendor mitigations if available
  • Discontinue use of the product if no mitigations are available

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

CISA KEV required action

05

Timeline

  1. May 31, 2024 · May 31, 2024
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 9, 2024 · Jul 9, 2024
    Confirmed exploited (CISA KEV)
    CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
  3. Jul 30, 2024 · Jul 30, 2024
    CISA remediation deadline
    Federal agencies are required to remediate by this date.
  4. Aug 11, 2026 · Aug 11, 2026
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →