s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2024-4999

📛 CVE Title

Ligowave Unity/Pro/Mimo/APC Arbitrary Command Injection

Description

A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352.

Overview

State
PUBLISHED
Assigner (CNA)
ONEKEY
CVSS severity
CRITICAL
CVSS score
CVSS 9.4 / 10 9.4 9.4 / 10
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
Effective score
9.4 / 10 CRITICAL source: CNA overview
CWE(s)
CWE-77
Reserved
2024-05-16
Published
2024-05-16 14:14 UTC
Last updated
2024-08-01 22:55 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/4xxx/CVE-2024-4999.json
Linked Threat
CVE-2024-4999 — Ligowave Unity/Pro/Mimo/APC Arbitrary Command Injection

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2024-44546
Assigner
ONEKEY
Published
May 16, 2024, 12:14:51 PM
Updated
Aug 1, 2024, 8:55:10 PM
EUVD base score (CVSS 4.0)
9.4 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
EUVD-reported EPSS
3.1100
Vendors
Ligowave
Products
Unity (0 ≤6.95-2)
MIMO (0 ≤6.95-1.rt2880)
APC Propeller (0 ≤2-5.95-4.rt3352)
Pro (0 ≤6.95-1.rt3883)
Unity (0 ≤6.95-2)
Pro (0 ≤6.95-1.rt3883)
Aliases
GHSA-736m-p2gm-v4q7

ENISA description: A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352.

EUVD references (1)

Affected products (4)

VendorProductVersionsPlatforms
Ligowave UNITY 0 (affected)
Ligowave PRO 0 (affected)
Ligowave MIMO 0 (affected)
Ligowave APC Propeller 0 (affected)

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Indicators (1)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
domain privileges.this no local data 2026-05-18 21:20 UTC

Flagged vendors

    Remediations (18)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:cyberpress.org

      Microsoft's July 2026 Patch Tuesday delivered its largest security update ever, resolving 570 vulnerabilities across its product ecosystem while addressing three zero-day flaws, two of which attackers actively exploited before patches were available.

      2026-08-05 15:27 UTC
    • web:learn.microsoft.com

      Learning path Learn how Microsoft supports secure software development as part of a cybersecurity solution - Training Secure software development means integrating security into each phase of your development lifecycle, from requirements analysis to maintenance. Microsoft provides many services that can help you develop more secure code and deploy a more secure application in the cloud. This ...

      2026-08-05 15:27 UTC
    • web:msrc.microsoft.com

      Security Update Guide - Microsoft Security Response Center

      2026-08-05 15:27 UTC
    • web:nvd.nist.gov

      Description In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer Pass pointer reference to amdgpu_bo_unref to clear the correct pointer, otherwise amdgpu_bo_unref clear the local variable, the original pointer not set to NULL, this could cause use-after-free bug.

      2026-08-05 15:27 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-08-05 15:27 UTC
    • web:www.microsoft.com

      These Knowledge Base articles accompany all security updates and advisories, and include caveats or known issues with security updates. Additionally, support engineers document common concerns from customers in these KB articles. These Knowledge Base articles are published the Security Update Guide with each release on Patch Tuesday.

      2026-08-05 15:27 UTC
    • web:www.microsoft.com

      Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed. You can choose the type of updates for which you want to be notified: Major ...

      2026-08-05 15:27 UTC
    • web:www.nist.gov

      NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.

      2026-08-05 15:27 UTC
    • web:robertsspaceindustries.com

      Hi Everyone! Time again for another Hotfix Central thread to keep you all up to date on things going on outside of the normal patch cycle in SC Alpha 4.8 LIVE! This will be a living document of...

      2026-05-22 10:39 UTC
    • web:translate.google.com

      Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.

      2026-05-22 10:39 UTC
    • web:wa.me

      Hosted by WhatsApp 2026 © WhatsApp LLC Privacy & Terms

      2026-05-22 10:39 UTC
    • web:hazards.fema.gov

      Access the FEMA Mitigation Planning Portal to manage and update your mitigation plans securely.

      2026-05-22 10:39 UTC
    • web:hi.service-now.com

      The Now Support portal is your launchpad to access self-help, get technical support, and manage your ServiceNow instances. Log in to manage upgrades, follow changes, view knowledge content, and more. Formerly HI portal.

      2026-05-22 10:39 UTC
    • web:web.whatsapp.com

      Log in to WhatsApp Web for simple, reliable and private messaging on your desktop. Send and receive messages and files with ease, all for free.

      2026-05-22 10:39 UTC
    • web:www.fool.com

      DoorDash (DASH) Q4 2025 Earnings Call Transcript DATE Wednesday, Feb. 18, 2026 at 5 p.m. ET CALL PARTICIPANTS Co-Founder, Chair, and Chief Executive Officer — Tony Xu Chief Financial Officer ...

      2026-05-22 10:39 UTC
    • web:nvd.nist.gov

      Vulnerabilities All vulnerabilities in the NVD have been assigned a CVE identifier and thus, abide by the definition below. CVE defines a vulnerability as: "A weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, or availability. Mitigation of the vulnerabilities in this ...

      2026-05-22 10:39 UTC
    • web:www.forbes.com

      Microsoft Exchange users are urged to mitigate a zero-day vulnerability that CISA has confirmed is under active exploitation.

      2026-05-22 10:39 UTC
    • web:www.gazettenet.com

      GAZETTE FILE PHOTO AMHERST — A dozen administrators in the Amherst and Amherst-Pelham Regional schools are accusing Superintendent E. Xiomara Herman of threats of physical harm, creating a ...

      2026-05-22 10:39 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2024-4999.json.

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:ligowave:unity:6.95-2:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "unity",
                "vendor": "ligowave",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.95-2"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:ligowave:pro:6.95-1.rt3883:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "pro",
                "vendor": "ligowave",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.95-1.rt3883"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:ligowave:mimo:6.95-1.rt2880:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mimo",
                "vendor": "ligowave",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.95-1.rt2880"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:ligowave:apc_propeller:2-5.95-4.rt3352:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "apc_propeller",
                "vendor": "ligowave",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2-5.95-4.rt3352"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-4999",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-16T15:17:05.688626Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:53:18.448Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:55:10.386Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "third-party-advisory",
                  "x_transferred"
                ],
                "url": "https://onekey.com/blog/security-advisory-remote-code-execution-in-ligowave-devices/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "UNITY",
              "vendor": "Ligowave",
              "versions": [
                {
                  "lessThanOrEqual": "6.95-2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "PRO",
              "vendor": "Ligowave",
              "versions": [
                {
                  "lessThanOrEqual": "6.95-1.rt3883",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "MIMO",
              "vendor": "Ligowave",
              "versions": [
                {
                  "lessThanOrEqual": "6.95-1.rt2880",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "APC Propeller",
              "vendor": "Ligowave",
              "versions": [
                {
                  "lessThanOrEqual": "2-5.95-4.rt3352",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Quentin Kaiser from ONEKEY Research Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote&nbsp;attacker to execute arbitrary commands with elevated privileges.<p>This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352.</p>"
                }
              ],
              "value": "A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote\u00a0attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "YES",
                "Recovery": "USER",
                "Safety": "NEGLIGIBLE",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "HIGH",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "DIFFUSE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/V:D/RE:M/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "MODERATE"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-16T12:17:49.310Z",
            "orgId": "2d533b80-6e4a-4e20-93e2-171235122846",
            "shortName": "ONEKEY"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://onekey.com/blog/security-advisory-remote-code-execution-in-ligowave-devices/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Ligowave Unity/Pro/Mimo/APC Arbitrary Command Injection",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This product being EOL, Ligowave will not patch the vulnerability. If replacement of the EOL device is not possible, ensure access to the administration interface is restricted to administration network zones only, to reduce likelihood of exploitation."
                }
              ],
              "value": "This product being EOL, Ligowave will not patch the vulnerability. If replacement of the EOL device is not possible, ensure access to the administration interface is restricted to administration network zones only, to reduce likelihood of exploitation."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "2d533b80-6e4a-4e20-93e2-171235122846",
        "assignerShortName": "ONEKEY",
        "cveId": "CVE-2024-4999",
        "datePublished": "2024-05-16T12:14:51.671Z",
        "dateReserved": "2024-05-16T12:06:27.762Z",
        "dateUpdated": "2024-08-01T20:55:10.386Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }