PT-2024-31449 · Unknown · Uci Idol 2

Ludwig Stage

+1

·

Published

2024-08-21

·

Updated

2025-09-03

·

CVE-2024-45166

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UCI IDOL 2 versions through 2.12
Description An issue was discovered in UCI IDOL 2 due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer. This issue makes UCI IDOL 2 vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. There is an access violation and EIP overwrite after five logins.
Recommendations For UCI IDOL 2 versions through 2.12, consider disabling the login functionality until a patch is available to prevent potential Denial-of-Service (DoS) attacks and remote code execution. Restrict access to the system to minimize the risk of exploitation. Avoid using the system for critical operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2024-45166

Affected Products

Uci Idol 2