CVE-2024-1748
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 22, 2024
Updated: Dec 31, 2024
CWE ID 502
Summary
CVE-2024-1748 is a critical vulnerability identified in van_der_Schaar LAB AutoPrognosis 0.1.21. The issue lies within the function load_model_from_file of the Release Note Handler component, leading to deserialization manipulation. This vulnerability can be exploited remotely, with a relatively high level of complexity and difficulty. The exploit has been made public, increasing the risk of potential attacks. VDB-254530 is the assigned identifier for this vulnerability, and the vendor was contacted but failed to respond to the disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.