CVE-2024-51954

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 3, 2025
Updated: Mar 6, 2025
CWE ID 284

Summary

CVE-2024-51954 is a newly disclosed vulnerability affecting ArcGIS Server versions 10.9.1 through 11.3 on both Windows and Linux platforms. This issue involves inadequate access control, enabling a remote, authenticated attacker with low privileges to potentially gain unauthorized access to protected services published on a standalone (unfederated) ArcGIS Server instance. If exploited, this vulnerability can lead to significant data breaches, posing a high risk to confidentiality, while having minimal impact on integrity and no impact on availability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share