PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-39703 ThreatQuotient CVE debrief

A command injection vulnerability in the ThreatQuotient ThreatQ Platform API endpoint allows authenticated attackers to achieve remote code execution. The flaw exists in versions prior to 5.29.3 and was disclosed by CISA on December 17, 2024. The vulnerability requires low privileges and no user interaction, making it exploitable by any authenticated user with network access to the platform.

Vendor
ThreatQuotient
Product
ThreatQ Platform
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-12-17
Original CVE updated
2024-12-17
Advisory published
2024-12-17
Advisory updated
2024-12-17

Who should care

Organizations using ThreatQuotient ThreatQ Platform for threat intelligence management, SOC teams relying on ThreatQ for indicator enrichment and analysis, security architects designing API security for threat intelligence platforms, and CISOs responsible for third-party security tooling risk assessment.

Technical summary

The ThreatQuotient ThreatQ Platform contains a command injection vulnerability in its API endpoint. An attacker with authenticated access can inject arbitrary commands that execute on the underlying system, resulting in remote code execution. The vulnerability is rated CVSS 3.1 8.8 (HIGH) due to its network accessibility, low complexity, and high impact across confidentiality, integrity, and availability. The attack requires only low privileges and no user interaction. ThreatQuotient has released version 5.29.3 to address this vulnerability.

Defensive priority

critical

Recommended defensive actions

  • Upgrade ThreatQ Platform to version 5.29.3 or later immediately
  • Restrict network access to ThreatQ Platform API endpoints to authorized administrative hosts only
  • Monitor API logs for suspicious command execution patterns or unexpected shell activity
  • Review and validate all API input sanitization and command execution paths
  • Apply principle of least privilege to ThreatQ Platform user accounts
  • Consider network segmentation to isolate ThreatQ Platform from untrusted networks

Evidence notes

CISA ICS advisory ICSA-24-352-01 published December 17, 2024 confirms command injection in ThreatQ Platform API endpoint prior to version 5.29.3. CVSS 3.1 score of 8.8 (HIGH) with vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates network exploitable, low attack complexity, low privileges required, no user interaction, with high impact to confidentiality, integrity, and availability.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-39703 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-39703

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-39703 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-39703

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-352-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-352-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.