CVE-2024-7294
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Oct 9, 2024
Updated: Oct 15, 2024
CWE ID 400
Summary
CVE-2024-7294 is a denial-of-service (DoS) vulnerability affecting In Progress® Telerik® Report Server versions before Q3 2024 (10.2.24.806). Anonymous endpoints on the server are at risk, as they can be targeted with HTTP traffic overloading, leading to server unavailability. The absence of rate limiting exacerbates the impact, making it essential for organizations using these versions to apply the forthcoming patch to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Progress Publishers