IM
IronMonkey Threat Research

CVE-2024-8518 LOW

Published: 2024-10-08 | Last Modified: 2026-04-15 | Status: Deferred

Description

CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted project file is loaded by an application user.

Additional Descriptions (1)

CWE-20: Existe una vulnerabilidad de validación de entrada incorrecta que podría provocar un bloqueo de la aplicación Zelio Soft 2 cuando un usuario de la aplicación carga un archivo de proyecto especialmente manipulado.

CVSS Metrics

Base Score: 3.3 (LOW)

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactLOW

Source: [email protected]

Type: Secondary

Exploitability Score: 1.8

Impact Score: 1.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-20
Notification
Message here