PMB Services Security Update Advisory

Overview

 

An update has been released to address vulnerabilities in the PMB service. Users of affected versions are advised to update to the latest version.

 

Affected Products

 

PMB Service

  • 7.4.1 (inclusive) to 7.4.9 (excluded)
  • 7.3.1 (inclusive) to 7.3.18 (excluded)
  • 7.5.1 (inclusive) to 7.5.6-2 (excluded)

 

Resolved Vulnerabilities

 

Remote code execution vulnerability in the PMB service (CVE-2024-26289)

 

Vulnerability Patches

 

Vulnerability patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

PMB Services versions 7.5.6-2, 7.5.7, 7.4.9, and 7.3.18

 

Referenced Sites

 

[1] CVE-2024-26289 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-26289

[2] CNW-2024-A-012: Remote Code Inclusion Vulnerability in Multiple PMB Versions

https://github.com/enisaeu/CNW/blob/main/advisories/2024/CNW-2024-A-12.md

[3] https://forge.sigb.net/projects/pmb/files