CVE-2024-38291

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 27, 2025
Updated: Feb 28, 2025
CWE ID 284
CWE ID 522

Summary

CVE-2024-38291 is a newlydiscovered vulnerability affecting the XIQ-SE system before version 24.2.11. This issue grants low-privileged users unauthorized access to admin passwords, posing a significant risk for privilege escalation attacks. By exploiting this vulnerability, an attacker can elevate their privileges and gain unrestricted access to the affected system, potentially leading to data theft or unauthorized system modifications. The impact of this vulnerability is severe, as it bypasses the intended access control mechanisms, and all users are advised to update their XIQ-SE installations to the latest version to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share