216.73.217.22

CVE-2024-11075

· Published 19/11/2024 14:15 · Modified 19/11/2024 21:57

Labels: CVE-2024-11075 2024-11-19CVE-2024-11075CWE-250[email protected]

Essential information

Published
19/11/2024 14:15
Modified
19/11/2024 21:57
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References