PT-2024-25535 · Axiros · Axess Auto Configuration Server

Moritz Feldmann

·

Published

2024-06-24

·

Updated

2024-10-21

·

CVE-2024-33898

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Axiros AXESS Auto Configuration Server (ACS) versions 4.x through 5.0.0
Description The issue is related to Incorrect Access Control, allowing an authorization bypass that enables remote attackers to achieve unauthenticated remote code execution.
Recommendations For versions 4.x through 5.0.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-33898

Affected Products

Axess Auto Configuration Server