CVE-2024-34520

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 12, 2025
Updated: Feb 13, 2025
CWE ID 639

Summary

CVE-2024-34520 is a newly identified vulnerability affecting the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0. This issue involves an authorization bypass, allowing authenticated 'guest' users to surpass client-side access controls and gain unauthorized administrative access. Users can potentially misuse this vulnerability to add new accounts and perform other unauthorized actions, posing a significant security risk. Organizations running this version of the Mavenir SCE Application Provisioning Portal are advised to apply the necessary patches as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share