CVE-2024-1748

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 22, 2024
Updated: Dec 31, 2024
CWE ID 502

Summary

CVE-2024-1748 is a critical vulnerability identified in van_der_Schaar LAB AutoPrognosis 0.1.21. The issue lies within the function load_model_from_file of the Release Note Handler component, leading to deserialization manipulation. This vulnerability can be exploited remotely, with a relatively high level of complexity and difficulty. The exploit has been made public, increasing the risk of potential attacks. VDB-254530 is the assigned identifier for this vulnerability, and the vendor was contacted but failed to respond to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share