IM
IronMonkey Threat Research

CVE-2024-28023 MEDIUM

Published: 2024-06-11 | Last Modified: 2026-04-15 | Status: Deferred

Description

A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

Additional Descriptions (1)

Existe una vulnerabilidad en el mecanismo de cola de mensajes que, si se explota, puede provocar la exposición de recursos o funcionalidades a actores no deseados, posiblemente proporcionando a los atacantes información confidencial o incluso ejecutar código arbitrario.

CVSS Metrics

Base Score: 5.7 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactLOW
Integrity ImpactLOW
Availability ImpactLOW

Source: [email protected]

Type: Secondary

Exploitability Score: 1.5

Impact Score: 3.7

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-259
Notification
Message here