PT-2025-2774 · Wazuh+1 · Wazuh+1

Frozzipies

·

Published

2025-02-03

·

Updated

2025-02-11

·

CVE-2024-47770

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Wazuh versions prior to 4.9.1
Description: This issue occurs when the system has weak privilege access, allowing an attacker to perform privilege escalation. As a result, an attacker can view the agent list on the Wazuh dashboard without privilege access. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations: For versions prior to 4.9.1, upgrade to version 4.9.1 to resolve the issue. As a temporary workaround, consider restricting access to the Wazuh dashboard to minimize the risk of exploitation. There are no known workarounds for this vulnerability.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2024-47770
GHSA-648Q-8M78-5CWV
GO-2025-3445
OPENSUSE-SU-2025:14732-1
OPENSUSE-SU-2025_0429-1
SUSE-SU-2025:0429-1

Affected Products

Suse
Wazuh