PT-2024-25701 · Unknown · Archer Platform

Published

2024-05-06

·

Updated

2026-01-28

·

CVE-2024-34093

CVSS v3.1

5.3

Medium

VectorAC:L/AV:N/A:N/C:L/I:N/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions Archer Platform versions prior to 2024.03
Description An issue was discovered in the Archer Platform, where an X-Forwarded-For Header Bypass vulnerability exists. This allows an unauthenticated attacker to potentially bypass intended whitelisting when the X-Forwarded-For header is enabled.
Recommendations For versions prior to 2024.03, update to a version 2024.03 or later to resolve the issue. As a temporary workaround, consider disabling the X-Forwarded-For header until a patch is available. Restrict access to sensitive areas of the platform to minimize the risk of exploitation.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-34093

Affected Products

Archer Platform