INITIALIZING
📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Multiple sectors HIGH 36m Global insider Cybersecurity Services CRITICAL 45m Global ransomware Multiple sectors (U.S. companies) CRITICAL 59m Global malware Financial Services, Cryptocurrency CRITICAL 1h Global malware Technology and Cloud Services HIGH 1h Global general Financial Services and E-commerce MEDIUM 1h Global data_breach Social Media and Communications CRITICAL 1h Global general Cybersecurity Operations HIGH 2h Global phishing Technology and Consumer Services HIGH 2h Global data_breach Multiple sectors HIGH 2h Global phishing Multiple sectors HIGH 36m Global insider Cybersecurity Services CRITICAL 45m Global ransomware Multiple sectors (U.S. companies) CRITICAL 59m Global malware Financial Services, Cryptocurrency CRITICAL 1h Global malware Technology and Cloud Services HIGH 1h Global general Financial Services and E-commerce MEDIUM 1h Global data_breach Social Media and Communications CRITICAL 1h Global general Cybersecurity Operations HIGH 2h Global phishing Technology and Consumer Services HIGH 2h Global data_breach Multiple sectors HIGH 2h Global phishing Multiple sectors HIGH 36m Global insider Cybersecurity Services CRITICAL 45m Global ransomware Multiple sectors (U.S. companies) CRITICAL 59m Global malware Financial Services, Cryptocurrency CRITICAL 1h Global malware Technology and Cloud Services HIGH 1h Global general Financial Services and E-commerce MEDIUM 1h Global data_breach Social Media and Communications CRITICAL 1h Global general Cybersecurity Operations HIGH 2h Global phishing Technology and Consumer Services HIGH 2h Global data_breach Multiple sectors HIGH 2h
Vulnerabilities

CVE-2024-23692

Critical 🇺🇸 CISA KEV ⚡ Exploit Available
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability — Rejetto HTTP File Server contains an improper neutralization of special elements used in
Published: Jul 9, 2024  ·  Source: CISA_KEV
CVSS v3
9.0
🔗 NVD Official
📄 Description (English)

Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability — Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.

🤖 AI Executive Summary

Rejetto HTTP File Server contains a template injection vulnerability allowing remote unauthenticated attackers to execute arbitrary commands via specially crafted HTTP requests. This critical flaw affects systems using vulnerable versions of the file server software.

📄 Description (Arabic)

يحتوي خادم ملفات Rejetto HTTP على ثغرة في معالجة عناصر محرك القوالب مما يسمح بحقن أوامر عشوائية. يمكن للمهاجمين استغلال هذه الثغرة دون الحاجة للمصادقة لتنفيذ أوامر على النظام المستهدف. تؤثر الثغرة على جميع الأنظمة التي تستخدم الإصدارات الضعيفة من البرنامج.

🤖 ملخص تنفيذي (AI)

خادم ملفات Rejetto HTTP يحتوي على ثغرة حقن القوالب التي تسمح للمهاجمين غير المصرحين بتنفيذ أوامر عشوائية عبر طلبات HTTP معدة خصيصاً. تؤثر هذه الثغرة الحرجة على الأنظمة التي تستخدم إصدارات ضعيفة من برنامج خادم الملفات.

🤖 AI Intelligence Analysis Analyzed: Apr 18, 2026 10:48
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
government banking energy healthcare telecom
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
9.0
/ 10.0
🔧 Remediation Steps (English)
Immediately update Rejetto HTTP File Server to the latest patched version. Disable or restrict access to the HTTP File Server if updates are unavailable. Implement network segmentation and firewall rules to limit exposure. Monitor for suspicious HTTP requests containing template injection payloads.
🔧 خطوات المعالجة (العربية)
قم بتحديث خادم ملفات Rejetto HTTP فوراً إلى أحدث إصدار مصحح. قم بتعطيل أو تقييد الوصول إلى خادم الملفات إذا لم تكن التحديثات متاحة. طبق تقسيم الشبكة وقواعد جدار الحماية لتقليل التعرض. راقب طلبات HTTP المريبة التي تحتوي على حمولات حقن القوالب.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.7.1 A.12.6.1 A.14.2.1
🔵 SAMA CSF
ID.BE-1 PR.AC-1 PR.PT-1 DE.CM-1
🟡 ISO 27001:2022
A.6.1.1 A.12.6.1 A.14.2.1 A.14.2.5
🔗 References & Sources 0
No references.
📦 Affected Products / CPE 1 entries
Rejetto:HTTP File Server
📊 CVSS Score
9.0
/ 10.0 — Critical
📋 Quick Facts
Severity Critical
CVSS Score9.0
EPSS94.30%
Exploit ✓ Yes
Patch ✓ Yes
CISA KEV🇺🇸 Yes
KEV Due Date2024-07-30
Published 2024-07-09
Source Feed cisa_kev
Views 1
🇸🇦 Saudi Risk Score
9.0
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
kev actively-exploited
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.