PT-2022-16671 · Unknown · Simple Diagnostics Agent

Yvan Genuer

·

Published

2022-03-08

·

Updated

2022-10-29

·

CVE-2022-24396

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Simple Diagnostics Agent versions 1.0 up to version 1.57
Description The issue concerns the lack of authentication checks for functionalities accessible via localhost on http port 3005. This allows an attacker to access administrative or privileged functionalities, potentially reading, modifying, or deleting sensitive information and configurations.
Recommendations For versions 1.0 up to version 1.57, consider restricting access to the http port 3005 to minimize the risk of exploitation. As a temporary workaround, limit the use of administrative functionalities until a proper authentication mechanism is implemented. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-24396

Affected Products

Simple Diagnostics Agent