CVSS 3.1 Score 9.8 of 10 (high)


Published Mar 13, 2024
Updated: Mar 14, 2024
CWE ID 287


CVE-2024-0799 is an authentication bypass vulnerability that affects Arcserve Unified Data Protection versions 9.2 and 8.1. The vulnerability exists in the wizardLogin function within the edge-app-base-webui.jar file. It has a CVSS score of 9.8, indicating a critical severity level. The exploitability score is 3.9, which suggests that it is relatively easy to exploit remotely without requiring any privileges or user interaction. The impact of this vulnerability on organizations is significant, with high potential for integrity and confidentiality impacts. To remediate the vulnerability, users should apply the latest patches or updates provided by Arcserve.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-0799 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options