PT-2024-16535 · Unknown · Appmanager

Manuel Stotz

+2

·

Published

2024-12-06

·

Updated

2024-12-06

·

CVE-2024-10776

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions AppManager (affected versions not specified)
Description The issue allows Lua apps to be deployed, removed, started, reloaded, or stopped without authorization via AppManager. This enables an attacker to remove legitimate apps, creating a denial-of-service (DoS) attack, read and write files, or load apps that utilize all features of the product available to a customer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-10776

Affected Products

Appmanager