IM
IronMonkey Threat Research

CVE-2024-2377 HIGH

Published: 2024-04-30 | Last Modified: 2026-04-15 | Status: Deferred

Description

A vulnerability exists in the too permissive HTTP response header web server settings of the SDM600. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information.

Additional Descriptions (1)

Existe una vulnerabilidad en la configuración del servidor web del encabezado de respuesta HTTP demasiado permisiva del SDM600. Un atacante puede aprovechar esto y posiblemente realizar acciones privilegiadas y acceder a información confidencial.

CVSS Metrics

Base Score: 7.6 (HIGH)

CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Attack VectorADJACENT_NETWORK
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionREQUIRED
ScopeCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 0.9

Impact Score: 6.0

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-346
Notification
Message here