PT-2024-22399 · Sipwise · Sipwise C5 Ngcp Dashboard

Adrian Tuchel

·

Published

2024-04-10

·

Updated

2025-06-17

·

CVE-2024-28345

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Sipwise C5 NGCP Dashboard versions prior to mr11.5.1
Description An issue in Sipwise C5 NGCP Dashboard allows a low-privileged user to access the "Journal endpoint" by directly visiting the URL.
Recommendations For versions prior to mr11.5.1, update to version mr11.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Journal endpoint until a patch is available.

Exploit

Fix

Related Identifiers

CVE-2024-28345

Affected Products

Sipwise C5 Ngcp Dashboard