CVE-2024-11944 Details
Description
iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of iXsystems TrueNAS devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tarfile.extractall method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-25626.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 30, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.truenas.com/docs/core/13.0/gettingstarted/corereleasenotes/#130-u63 | [email protected] | Release Notes |
| https://www.zerodayinitiative.com/advisories/ZDI-24-1643/ | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ixsystems truenas firmware | 13.0 - 13.0 beta1 13.0 rc1 13.0 u1 13.0 u1.1 13.0 u2 13.0 u3 13.0 u3.1 13.0 u4 13.0 u5 13.0 u5.1 13.0 u5.2 13.0 u5.3 13.0 u6 13.0 u6.1 13.0 u6.2 |
CPE
Remediation
| |
| ixsystems truenas | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 18, 2025 | Initial Analysis | [email protected] |
| Dec 30, 2024 | New CVE Received | [email protected] |