CVE-2024-7108

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 26, 2024
Updated: Oct 3, 2024
CWE ID 863

Summary

CVE-2024-7108 is a new authorization vulnerability that has been identified in National Keep Cyber Security Services' CyberMath software. This issue allows unauthorized access to functionality that should be restricted based on Access Control Lists (ACLs). The vulnerability affects CyberMath versions prior to CYBM.240816253. An attacker could exploit this vulnerability to gain privileged access and potentially take control of affected systems, leading to significant security risks for organizations using this software. It is crucial for users to apply the necessary patch or upgrade as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share