RULE(RULE ID:338453)

Rule General Information
Release Date: 2024-10-09
Rule Name: Topsec Operation and Maintenance Security Audit System synRequest Remote Command Execution Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: TopSAG, the TopSec operation and maintenance security audit system, is developed based on the independent intellectual property NGTOS security operating system platform and years of experience in network security protection. The system is based on the 4A management concept and has security agents as its core. It continuously innovates in the field of operation and maintenance management, providing customers with comprehensive operation and maintenance security solutions including pre prevention, in-process monitoring, and post audit. It is suitable for industries such as government, finance, energy, telecommunications, transportation, and education. There is a remote command execution vulnerability in the synRequest security audit system of Topsec operation and maintenance. The incoming data has not been verified, and command injection can be achieved through special injection symbols.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.