{"cveID":"CVE-2024-23692","vendorProject":"Rejetto","product":"HTTP File Server","vulnerabilityName":"Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability","dateAdded":"2024-07-09","shortDescription":"Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2024-07-30","knownRansomwareCampaignUse":"Known","notes":"The patched Rejetto HTTP File Server (HFS) is version 3: https://github.com/rejetto/hfs?tab=readme-ov-file#installation, https://www.rejetto.com/hfs/ ;   https://nvd.nist.gov/vuln/detail/CVE-2024-23692","cwes":["CWE-1336"],"year":2024,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2024-23692","technique":"T1221","technique_name_at_mapping":"Template Injection","mapping_type":"exploitation_technique","capability_group":"other","comments":"CVE-2024-23692 is a OS command injection vulnerability within the HTTP File Server (HFS) process for Rejetto. It has been reported to be exploited by threat actors to deploy cryptomining malware, install backdoors, Remote Access Trojans (RATs), and other malware like “GoThief” to exfiltrate sensitive data. ","references":["https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/","https://thehackernews.com/2024/07/ukrainian-institutions-targeted-using.html","https://www.bleepingcomputer.com/news/security/hackers-attack-hfs-servers-to-drop-malware-and-monero-miners/","https://socradar.io/critical-http-file-server-vulnerability-cve-2024-23692-actively-exploited-to-deploy-cryptomining-malware-rats-stealers/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2024-23692","technique":"T1005","technique_name_at_mapping":"Data from Local System","mapping_type":"secondary_impact","capability_group":"other","comments":"CVE-2024-23692 is a OS command injection vulnerability within the HTTP File Server (HFS) process for Rejetto. It has been reported to be exploited by threat actors to deploy cryptomining malware, install backdoors, Remote Access Trojans (RATs), and other malware like “GoThief” to exfiltrate sensitive data. ","references":["https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/","https://thehackernews.com/2024/07/ukrainian-institutions-targeted-using.html","https://www.bleepingcomputer.com/news/security/hackers-attack-hfs-servers-to-drop-malware-and-monero-miners/","https://socradar.io/critical-http-file-server-vulnerability-cve-2024-23692-actively-exploited-to-deploy-cryptomining-malware-rats-stealers/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2024-23692","technique":"T1082","technique_name_at_mapping":"System Information Discovery","mapping_type":"primary_impact","capability_group":"other","comments":"CVE-2024-23692 is a OS command injection vulnerability within the HTTP File Server (HFS) process for Rejetto. It has been reported to be exploited by threat actors to deploy cryptomining malware, install backdoors, Remote Access Trojans (RATs), and other malware like “GoThief” to exfiltrate sensitive data. ","references":["https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/","https://thehackernews.com/2024/07/ukrainian-institutions-targeted-using.html","https://www.bleepingcomputer.com/news/security/hackers-attack-hfs-servers-to-drop-malware-and-monero-miners/","https://socradar.io/critical-http-file-server-vulnerability-cve-2024-23692-actively-exploited-to-deploy-cryptomining-malware-rats-stealers/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2024-23692","technique":"T1105","technique_name_at_mapping":"Ingress Tool Transfer","mapping_type":"secondary_impact","capability_group":"other","comments":"CVE-2024-23692 is a OS command injection vulnerability within the HTTP File Server (HFS) process for Rejetto. It has been reported to be exploited by threat actors to deploy cryptomining malware, install backdoors, Remote Access Trojans (RATs), and other malware like “GoThief” to exfiltrate sensitive data. ","references":["https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/","https://thehackernews.com/2024/07/ukrainian-institutions-targeted-using.html","https://www.bleepingcomputer.com/news/security/hackers-attack-hfs-servers-to-drop-malware-and-monero-miners/","https://socradar.io/critical-http-file-server-vulnerability-cve-2024-23692-actively-exploited-to-deploy-cryptomining-malware-rats-stealers/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2024-23692","technique":"T1496","technique_name_at_mapping":"Resource Hijacking","mapping_type":"secondary_impact","capability_group":"other","comments":"CVE-2024-23692 is a OS command injection vulnerability within the HTTP File Server (HFS) process for Rejetto. It has been reported to be exploited by threat actors to deploy cryptomining malware, install backdoors, Remote Access Trojans (RATs), and other malware like “GoThief” to exfiltrate sensitive data. ","references":["https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/","https://thehackernews.com/2024/07/ukrainian-institutions-targeted-using.html","https://www.bleepingcomputer.com/news/security/hackers-attack-hfs-servers-to-drop-malware-and-monero-miners/","https://socradar.io/critical-http-file-server-vulnerability-cve-2024-23692-actively-exploited-to-deploy-cryptomining-malware-rats-stealers/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1005","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data from Local System","name_at_mapping":"Data from Local System","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":14,"has_detection_strategy":true},{"id":"T1082","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"System Information Discovery","name_at_mapping":"System Information Discovery","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":33,"has_detection_strategy":true},{"id":"T1105","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Ingress Tool Transfer","name_at_mapping":"Ingress Tool Transfer","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":87,"has_detection_strategy":true},{"id":"T1221","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Template Injection","name_at_mapping":"Template Injection","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":2,"has_detection_strategy":true},{"id":"T1496","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Resource Hijacking","name_at_mapping":"Resource Hijacking","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":13,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}