CVE-2024-37774
CVSS 3.1 Score 8 of 10 (high)
Details
Summary
CVE-2024-37774 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Sunbird DCIM's dcTrack v9.1.2. Authenticated attackers can exploit this issue to manipulate admin screens and escalate their privileges, potentially gaining access to sensitive information or functionality, putting the security of the affected system at risk. This vulnerability allows attackers to force an Administrator user to perform unintended actions, increasing the attack surface and potentially leading to significant consequences. It is essential that organizations using this version of Sunbird DCIM apply the necessary patches as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.