PT-2025-16113 · Unknown+1 · Taegis Endpoint Agent+1

CVE-2024-13861

·

Published

2025-04-11

·

Updated

2025-05-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Taegis Endpoint Agent (Linux) versions prior to 1.3.10
Description: A code injection issue in the Debian package component allows local users to execute arbitrary code as root. This issue does not affect Redhat-based systems that use RPM packages.
Recommendations: For versions prior to 1.3.10, update to version 1.3.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the Debian package component to minimize the risk of exploitation.

Fix

Code Injection

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13861

Affected Products

Debian
Taegis Endpoint Agent