IM
IronMonkey Threat Research

CVE-2024-9005 HIGH

Published: 2024-10-08 | Last Modified: 2026-04-15 | Status: Deferred

Description

CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server.

Additional Descriptions (1)

CWE-502: Existe una vulnerabilidad de deserialización de datos no confiables que podría permitir que se ejecute código de forma remota en el servidor cuando se publican datos deserializados de forma no segura en el servidor web.

CVSS Metrics

Base Score: 7.3 (HIGH)

CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorNETWORK
Attack ComplexityHIGH
Attack RequirementsNONE
Privileges RequiredLOW
User InteractionACTIVE
Vulnerability ConfidentialityHIGH
Vulnerability IntegrityHIGH
Vulnerability AvailabilityHIGH
Subsequent ConfidentialityNONE
Subsequent IntegrityNONE
Subsequent AvailabilityNONE

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-502
Notification
Message here