Vulnerability record · CVE-2024-23692 · published 31 May 2024
CVE-2024-23692: Rejetto HTTP File Server template injection leads to unauthenticated RCE
Rejetto · Http File Server
Rejetto HTTP File Server through version 2.3m is vulnerable to template injection, allowing a remote unauthenticated attacker to execute arbitrary commands via a crafted HTTP request. The flaw is critical because it requires no credentials or user interaction and the affected version is no longer supported, so no vendor patch is expected.
Description
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, KEV listing with known ransomware use, near-maximum EPSS, and public exploit code make this an urgent patch-or-remove case.
What it is
Rejetto HTTP File Server through version 2.3m is vulnerable to template injection, allowing a remote unauthenticated attacker to execute arbitrary commands via a crafted HTTP request. The flaw is critical because it requires no credentials or user interaction and the affected version is no longer supported, so no vendor patch is expected.
Impact
An attacker gains arbitrary command execution on the host running HFS, typically leading to full system compromise under the service account. Given KEV listing with known ransomware use, this can serve as an initial access vector for broader intrusion.
Attack surface
Reachable over the network through the HFS HTTP interface; the CVSS vector shows no privileges required and no user interaction, so any exposed instance is directly attackable.
Exploitation
CVE-2024-23692 is in CISA KEV with known ransomware campaign use, EPSS probability is about 0.995 (99.9th percentile), and multiple references are tagged Exploit including a Metasploit module, indicating active and public exploitation.
What to do
- Discontinue use of Rejetto HFS 2.3m or migrate to a supported file server, since the affected version is end-of-life and no vendor patch exists.
- If HFS must remain, remove it from internet exposure and restrict access to trusted internal networks only.
- Apply vendor or CISA-recommended mitigations and compensating controls such as network segmentation and least-privilege service accounts.
- Hunt for and remove any existing HFS installations, then verify no unauthorized persistence or web shells were left behind.
- Monitor CISA KEV guidance and apply the required action by the listed due date.
Detection
- Inspect HTTP request logs for HFS template syntax or macro expressions in request parameters, headers, or paths.
- Alert on HFS process spawning child processes such as cmd.exe, powershell.exe, or /bin/sh.
- Search hosts for hfs.exe or Rejetto HFS artifacts and correlate with outbound connections or new listening services.
- Review network traffic to HFS ports for anomalous POST or GET requests containing encoded command strings.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-23692 to the Known Exploited Vulnerabilities catalog on 9 July 2024 as "Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 30 July 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/rapid7/metasploit-framework/pull/19240 | ExploitIssue TrackingPatch |
| https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/ | Exploit |
| https://vulncheck.com/advisories/rejetto-unauth-rce | Third Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/19240 | ExploitIssue TrackingPatch |
| https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/ | Exploit |
| https://vulncheck.com/advisories/rejetto-unauth-rce | Third Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2024-23692-detect-rejetto-hfs-vulnerability | ExploitThird Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2024-23692-rejetto-hfs-mitigate-vulnerability | ExploitThird Party Advisory |
| https://www.vicarius.io/vsociety/posts/unauthenticated-rce-flaw-in-rejetto-http-file-server-cve-2024-23692 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23692 | US Government Resource |
Track CVE-2024-23692 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-23692), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.