CVE-2024-41970
CVSS 3.1 Score 5.7 of 10 (medium)
Details
Published Nov 18, 2024
CWE ID 732
Summary
CVE-2024-41970 is a newly disclosed vulnerability that allows a low privileged remote attacker to access forbidden diagnostic data. This issue arises due to incorrect permission assignment for critical resources. The vulnerability poses a potential risk as diagnostic data may contain sensitive information that, if accessed by unauthorized users, could lead to data breaches or system compromise. It is essential that affected organizations address this vulnerability promptly by implementing appropriate access controls to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.