PT-2024-35315 · Unknown · Automation Web Platform Wawp

Stealthcopter

·

Published

2024-11-22

·

Updated

2024-12-03

·

CVE-2024-52475

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Automation Web Platform Wawp versions prior to 3.0.18
Description The issue is related to an Authentication Bypass Using an Alternate Path or Channel vulnerability in the Automation Web Platform Wawp. This vulnerability allows authentication bypass.
Recommendations For versions prior to 3.0.18, update to version 3.0.18 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the platform to minimize the risk of exploitation.

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2024-52475

Affected Products

Automation Web Platform Wawp