RULE(RULE ID:338314)

Rule General Information
Release Date: 2024-08-13
Rule Name: Qiyuesuo ukeysign Remote Command Execution Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Qiyuesuo is a platform that provides electronic signing and seal management services. It collaborates with authoritative CA institutions, notary offices, and law firms to provide legal and effective electronic signature products for medium and large enterprises, meeting the needs of online signing and stamping, and supporting integration and docking with various business systems to achieve electronic signing of business processes. The Qiyuesuo ukeysign has a remote command execution vulnerability, which can be exploited by remote attackers to execute arbitrary commands or code on the server.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.