IM
IronMonkey Threat Research

CVE-2024-2378 HIGH

Published: 2024-04-30 | Last Modified: 2026-04-15 | Status: Deferred

Description

A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privileges on af-fected installations.

Additional Descriptions (1)

Existe una vulnerabilidad en el componente de autenticación web del SDM600. Si es explotado, un atacante podría aumentar los privilegios de las instalaciones afectadas.

CVSS Metrics

Base Score: 8.0 (HIGH)

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack VectorADJACENT_NETWORK
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 1.3

Impact Score: 6.0

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-863
Notification
Message here