AI analysis
Ahsay AhsayCBS through version 10.3.2 has an OS command injection flaw in the Replication Receiver component, in the /rps/api/json/UpdateReceivers.do endpoint. A remote attacker can trigger it by manipulating the random argument, with no authentication and no user interaction required. Successful exploitation can execute operating-system commands with the privileges of the backup server, with high impact to confidentiality, integrity, and availability of that host and potentially of connected systems. Organizations running AhsayCBS at or below 10.3.2 are affected; upgrading to 10.3.4 fixes the issue. The advisory states that an exploit has been published and may be used, but the flaw is not in CISA KEV and confirmed in-the-wild exploitation is not reported.
What to do: Upgrade AhsayCBS to version 10.3.4. Until that is done, limit network access to the replication receiver API so only trusted hosts can reach /rps/api/json/UpdateReceivers.do, and review logs for unexpected requests to that endpoint.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised.