PT-2025-16113 · Unknown+1 · Taegis Endpoint Agent+1
Published
2025-04-11
·
Updated
2025-05-07
·
CVE-2024-13861
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Taegis Endpoint Agent (Linux) versions prior to 1.3.10
Description:
A code injection issue in the Debian package component allows local users to execute arbitrary code as root. This issue does not affect Redhat-based systems that use RPM packages.
Recommendations:
For versions prior to 1.3.10, update to version 1.3.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the Debian package component to minimize the risk of exploitation.
Fix
Code Injection
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Taegis Endpoint Agent