PT-2024-28787 · Unknown+1 · Solar-Log 300+6

Nepenthe0320

·

Published

2024-07-26

·

Updated

2024-11-11

·

CVE-2024-40117

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Solar-Log 1000 versions prior to v2.8.2 and build 52- 23.04.2013 Solar-Log 250, 300, 1200, 2000, SL 50 Gateway versions prior to 4.2.8 SL Base versions prior to 5.1.2 and 6.0.0
Description The issue is related to incorrect access control, allowing attackers to obtain administrative privileges by connecting to the web administration server. This does not affect SL 200, 500, 1000.
Recommendations For Solar-Log 1000 versions prior to v2.8.2 and build 52- 23.04.2013, update to version v2.8.2 or later. For Solar-Log 250, 300, 1200, 2000, SL 50 Gateway versions prior to 4.2.8, update to version 4.2.8 or later. For SL Base versions prior to 5.1.2 and 6.0.0, update to version 5.1.2 or 6.0.0 or later.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-40117

Affected Products

Sl 50 Gateway
Sl Base
Solar-Log 1000
Solar-Log 1200
Solar-Log 2000
Solar-Log 250
Solar-Log 300