CVE-2024-54764

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 6, 2025
Updated: Jan 7, 2025

Summary

CVE-2024-54764 is a newly disclosed access control vulnerability affecting the /login/hostinfo2.cgi component in ipTIME A2004 v12.17.0. This issue allows unauthenticated attackers to gain access to sensitive information, posing a significant risk to system security. The vulnerability lies in the component's access control mechanism, which fails to properly restrict access to the data. Attackers can exploit this weakness to bypass authentication and retrieve sensitive information, potentially leading to data breaches or further unauthorized actions. It is crucial for ipTIME A2004 v12.17.0 users to apply the necessary patches or updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share