PT-2025-2774 · Wazuh+1 · Wazuh+1
Frozzipies
·
Published
2025-02-03
·
Updated
2025-02-11
·
CVE-2024-47770
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Wazuh versions prior to 4.9.1
Description:
This issue occurs when the system has weak privilege access, allowing an attacker to perform privilege escalation. As a result, an attacker can view the agent list on the Wazuh dashboard without privilege access. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations:
For versions prior to 4.9.1, upgrade to version 4.9.1 to resolve the issue. As a temporary workaround, consider restricting access to the Wazuh dashboard to minimize the risk of exploitation. There are no known workarounds for this vulnerability.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Wazuh