CVE-2024-54764
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-54764 is a newly disclosed access control vulnerability affecting the /login/hostinfo2.cgi component in ipTIME A2004 v12.17.0. This issue allows unauthenticated attackers to gain access to sensitive information, posing a significant risk to system security. The vulnerability lies in the component's access control mechanism, which fails to properly restrict access to the data. Attackers can exploit this weakness to bypass authentication and retrieve sensitive information, potentially leading to data breaches or further unauthorized actions. It is crucial for ipTIME A2004 v12.17.0 users to apply the necessary patches or updates as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.