Back to Labs
Security Advisory

CVE-2024-3444

About

A vulnerability was found in Wangshen SecGate 3600 up to 20240408. It has been classified as critical. This affects an unknown part of the file /?g=net_pro_keyword_import_save. The manipulation of the argument reqfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259701 was assigned to this vulnerability.

Weakness (CWE):CWE-434

Rainforest analyst review

This Wangshen SecGate 3600 issue allows an unrestricted file upload through a specific import endpoint, and a public exploit exists. The description labels it critical, but the scored reality is more contained: it requires high privileges to reach, and the rated confidentiality, integrity, and availability impacts are all low, which is why the number lands at 4.7 rather than in the nines.

So while 'unrestricted upload with public PoC on a security appliance' sounds alarming, the high-privilege gate means this is not an unauthenticated smash-and-grab. It's more relevant as something a user who already holds elevated access on the appliance can misuse, and the limited impact rating suggests the upload doesn't cleanly translate to full compromise on its own.

We deliberately rank this well below its 'critical' framing and align to the CVSS reality. The pragmatic controls are keeping the appliance's management surface off untrusted networks and keeping its privileged accounts few and watched. Public exploit code means we should confirm our version and monitor the endpoint, but the privilege precondition keeps this off the emergency list for a properly segmented deployment.

References

Related CVEs

Frequently asked questions

What is CVE-2024-3444?

A vulnerability was found in Wangshen SecGate 3600 up to 20240408. It has been classified as critical. This affects an unknown part of the file /?g=net_pro_keyword_import_save. The manipulation of the argument reqfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259701 was assigned to this vulnerability.

How severe is CVE-2024-3444?

CVE-2024-3444 carries a CVSS 3.1 base score of 4.7, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 54 out of 100, in the elevated band.

How is CVE-2024-3444 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L): attack vector Network, attack complexity Low, privileges required High, user interaction None. Impact on confidentiality Low, integrity Low and availability Low.

How do I fix CVE-2024-3444?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email