CVE-2024-48799
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 14, 2024
Updated: Oct 15, 2024
Summary
CVE-2024-48799 is a newly disclosed vulnerability affecting the com.lorexcorp.lorexping firmware update process from LOREX TECHNOLOGY INC. A remote attacker can exploit this issue to gain unauthorized access to sensitive information during the update process. The exact nature of the information obtained is not clear, but it poses a potential security risk. The vulnerability exists in version 1.4.22 of the software, and users are strongly encouraged to apply the forthcoming patch or upgrade to a secure version to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.