CVE-2024-9513
CVSS 3.1 Score 3.7 of 10 (low)
Details
Published Oct 4, 2024
Updated: Nov 13, 2024
CWE ID 203
Summary
CVE-2024-9513 is a newly disclosed vulnerability affecting NetAdmin IAM version 3.5 and below. The issue lies in the HTTP POST Request Handler's /controller/api/Answer/ReturnUserQuestionsFilled component, where manipulation of the 'username' argument exposes sensitive information due to a discrepancy. This vulnerability can be exploited remotely, with a high level of complexity and difficulty. The exploit has been made public, increasing the risk of potential attacks. The vendor is aware of the issue and will release a fix in mid-October 2024.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share