PT-2024-33285 · Paxton · Net2

Jeroen Hermans

·

Published

2024-10-21

·

Updated

2024-11-19

·

CVE-2024-48939

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Paxton Net2 versions prior to 6.07.14023.5015 (SR4)
Description Insufficient validation is performed on the REST API License file, enabling the use of the REST API with an invalid License File. This allows attackers to potentially retrieve access-log data. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For versions prior to 6.07.14023.5015 (SR4), upgrade to version 6.07.14023.5015 (SR4) or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API until the upgrade is applied.

Exploit

Fix

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-48939

Affected Products

Net2