CVE-2024-51954
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Mar 3, 2025
Updated: Mar 6, 2025
CWE ID 284
Summary
CVE-2024-51954 is a newly disclosed vulnerability affecting ArcGIS Server versions 10.9.1 through 11.3 on both Windows and Linux platforms. This issue involves inadequate access control, enabling a remote, authenticated attacker with low privileges to potentially gain unauthorized access to protected services published on a standalone (unfederated) ArcGIS Server instance. If exploited, this vulnerability can lead to significant data breaches, posing a high risk to confidentiality, while having minimal impact on integrity and no impact on availability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Esri