PT-2026-7655 · Cipplanner · Cipace

Publicado

2026-02-11

·

Atualizado

2026-02-12

·

CVE-2024-50618

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions CIPPlanner CIPAce versions prior to 9.17
Description A weakness exists in the Authentication component of CIPPlanner CIPAce that allows attackers to bypass a security measure. Specifically, the system’s reliance on single-factor authentication presents a risk. If the secret associated with this authentication method is compromised, an attacker could potentially gain full authentication, particularly when the system is configured to permit login with internal accounts.
Recommendations Update to version 9.17 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-50618

Produtos afetados

Cipace