PT-2025-2774 · Wazuh+1 · Wazuh+1

Frozzipies

·

Publicado

2025-02-03

·

Atualizado

2025-02-11

·

CVE-2024-47770

CVSS v3.1

8.0

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Wazuh versions prior to 4.9.1
Description: This issue occurs when the system has weak privilege access, allowing an attacker to perform privilege escalation. As a result, an attacker can view the agent list on the Wazuh dashboard without privilege access. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations: For versions prior to 4.9.1, upgrade to version 4.9.1 to resolve the issue. As a temporary workaround, consider restricting access to the Wazuh dashboard to minimize the risk of exploitation. There are no known workarounds for this vulnerability.

Exploit

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-47770
GHSA-648Q-8M78-5CWV
GO-2025-3445
OPENSUSE-SU-2025:14732-1
OPENSUSE-SU-2025_0429-1
SUSE-SU-2025:0429-1

Produtos afetados

Suse
Wazuh