216.73.216.233

CVE-2024-42017

· Published 30/09/2024 18:15 · Modified 29/10/2024 15:35

Labels: CVE-2024-42017 2024-09-30CVE-2024-42017CWE-306[email protected]

Essential information

Published
30/09/2024 18:15
Modified
29/10/2024 15:35
Author
Creator
CVSS
10.0 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an attacker to execute arbitrary commands with system privilege on the endpoint hosting the application, without any authentication.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References