216.73.217.22

CVE-2024-10381

· Published 25/10/2024 13:15 · Modified 14/11/2024 21:44

Labels: CVE-2024-10381 2024-10-25CVE-2024-10381CWE-288NVD-CWE-Other[email protected]

Essential information

Published
25/10/2024 13:15
Modified
14/11/2024 21:44
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable device. Successful exploitation of this vulnerability could allow remote attacker to gain unauthorized access and take complete control of the targeted device.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
matrixcomsec / cosec vega faxq firmware cpe:2.3:o:matrixcomsec:cosec_vega_faxq_firmware:*:*:*:*:*:*:*:*
matrixcomsec / cosec vega faxq cpe:2.3:h:matrixcomsec:cosec_vega_faxq:-:*:*:*:*:*:*:*

References