CVE-2024-37775
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Dec 16, 2024
Updated: Dec 17, 2024
CWE ID 863
Summary
CVE-2024-37775 is a new vulnerability affecting Sunbird DCIM dcTrack v9.1.2. This issue involves incorrect access control where an attacker can manipulate ticket locations, bypassing Role-Based Access Control (RBAC) checks. As a result, unauthorized users may be able to create or modify tickets, potentially leading to unintended consequences in the DCIM system. Organizations using this version of dcTrack are advised to apply the necessary patches or updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share