PT-2024-37346 · Vercom S.A. · Redlink Sdk

Maksymilian Motyl

·

Published

2024-09-30

·

Updated

2025-10-03

·

CVE-2024-6051

CVSS v4.0

4.3

Medium

VectorAV:L/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Clear
Name of the Vulnerable Software and Affected Versions: Redlink SDK versions through 1.13
Description: A Cross Application Scripting vulnerability is present in Vercom S.A. Redlink SDK. In certain cases, it allows local code injection and manipulation of the view of a vulnerable application.
Recommendations: For Redlink SDK versions through 1.13, update to a version later than 1.13 to resolve the issue. As a temporary workaround, consider restricting access to the Redlink SDK until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-6051

Affected Products

Redlink Sdk