PT-2024-29689 · Atos · Atos Eviden Icare

Published

2024-09-30

·

Updated

2024-10-29

·

CVE-2024-42017

CVSS v3.1

10

Critical

VectorAC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Atos Eviden iCare versions 2.7.1 through 2.7.11
Description The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an attacker to execute arbitrary commands with system privilege on the endpoint hosting the application, without any authentication.
Recommendations For Atos Eviden iCare versions 2.7.1 through 2.7.11, as a temporary workaround, consider restricting access to the locally exposed web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-42017

Affected Products

Atos Eviden Icare