---
cve: "CVE-2024-27773"
severity: "HIGH"
cvss: 8.8
epss: "36%"
vendor: "Unitronics"
kev: false
exploited: false
published: "2024-03-18 14:15:09"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T03:08:37+02:00"
---

# CVE-2024-27773

> 8.8 HIGH

## Beschreibung

Unitronics Unistream Unilogic – Versions prior to 1.35.227 -

CWE-348: Use of Less Trusted Source may allow RCE

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-348** — Use of Less Trusted Source
  The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.

## Angriffsmuster (CAPEC)

- [CAPEC-73 — User-Controlled Filename](https://capec.mitre.org/data/definitions/73.html) _(Severity: High)_
- [CAPEC-76 — Manipulating Web Input to File System Calls](https://capec.mitre.org/data/definitions/76.html) _(Severity: Very High)_
- [CAPEC-85 — AJAX Footprinting](https://capec.mitre.org/data/definitions/85.html) _(Severity: Low)_
- [CAPEC-141 — Cache Poisoning](https://capec.mitre.org/data/definitions/141.html) _(Severity: High)_
- [CAPEC-142 — DNS Cache Poisoning](https://capec.mitre.org/data/definitions/142.html) _(Severity: High)_

## ATT&CK-Techniken

- [T1557.002 — Adversary-in-the-Middle: ARP Cache Poisoning](https://attack.mitre.org/techniques/T1557/002/)
- [T1584.002 — Compromise Infrastructure: DNS Server](https://attack.mitre.org/techniques/T1584/002/)

## Referenzen

- <https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0>
- <https://claroty.com/team82/blog/new-critical-vulnerabilities-in-unitronics-unistream-devices-uncovered>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-27773) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
