PT-2024-29689 · Atos · Atos Eviden Icare
Published
2024-09-30
·
Updated
2024-10-29
·
CVE-2024-42017
CVSS v3.1
10
Critical
| Vector | AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions
Atos Eviden iCare versions 2.7.1 through 2.7.11
Description
The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an attacker to execute arbitrary commands with system privilege on the endpoint hosting the application, without any authentication.
Recommendations
For Atos Eviden iCare versions 2.7.1 through 2.7.11, as a temporary workaround, consider restricting access to the locally exposed web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atos Eviden Icare