PatchSiren cyber security CVE debrief
CVE-2024-39703 ThreatQuotient CVE debrief
A command injection vulnerability in the ThreatQuotient ThreatQ Platform API endpoint allows authenticated attackers to achieve remote code execution. The flaw exists in versions prior to 5.29.3 and was disclosed by CISA on December 17, 2024. The vulnerability requires low privileges and no user interaction, making it exploitable by any authenticated user with network access to the platform.
- Vendor
- ThreatQuotient
- Product
- ThreatQ Platform
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-17
- Original CVE updated
- 2024-12-17
- Advisory published
- 2024-12-17
- Advisory updated
- 2024-12-17
Who should care
Organizations using ThreatQuotient ThreatQ Platform for threat intelligence management, SOC teams relying on ThreatQ for indicator enrichment and analysis, security architects designing API security for threat intelligence platforms, and CISOs responsible for third-party security tooling risk assessment.
Technical summary
The ThreatQuotient ThreatQ Platform contains a command injection vulnerability in its API endpoint. An attacker with authenticated access can inject arbitrary commands that execute on the underlying system, resulting in remote code execution. The vulnerability is rated CVSS 3.1 8.8 (HIGH) due to its network accessibility, low complexity, and high impact across confidentiality, integrity, and availability. The attack requires only low privileges and no user interaction. ThreatQuotient has released version 5.29.3 to address this vulnerability.
Defensive priority
critical
Recommended defensive actions
- Upgrade ThreatQ Platform to version 5.29.3 or later immediately
- Restrict network access to ThreatQ Platform API endpoints to authorized administrative hosts only
- Monitor API logs for suspicious command execution patterns or unexpected shell activity
- Review and validate all API input sanitization and command execution paths
- Apply principle of least privilege to ThreatQ Platform user accounts
- Consider network segmentation to isolate ThreatQ Platform from untrusted networks
Evidence notes
CISA ICS advisory ICSA-24-352-01 published December 17, 2024 confirms command injection in ThreatQ Platform API endpoint prior to version 5.29.3. CVSS 3.1 score of 8.8 (HIGH) with vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates network exploitable, low attack complexity, low privileges required, no user interaction, with high impact to confidentiality, integrity, and availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-39703 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-39703
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-39703 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-39703
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-352-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-352-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.