CVE-2024-42207

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 5, 2025
CWE ID 384

Summary

CVE-2024-42207 is a session fixation vulnerability affecting HCL iAutomate. This issue allows an attacker to seize control of a victim's authenticated session by hijacking their session ID. Successful exploitation could lead to unauthorized access to the affected system, potentially resulting in data theft or other malicious activities. Users are advised to apply the necessary patches or updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share