A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list of the component Configuration Center. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
History

Fri, 01 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Knightliao
Knightliao disconf
CPEs cpe:2.3:a:knightliao:disconf:*:*:*:*:*:*:*:*
Vendors & Products Knightliao
Knightliao disconf
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 01 Nov 2024 04:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list of the component Configuration Center. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Title knightliao Disconf Configuration Center list improper authentication
Weaknesses CWE-287
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-11-01T04:31:03.775Z

Updated: 2024-11-01T14:22:44.724Z

Reserved: 2024-10-31T15:57:26.202Z

Link: CVE-2024-10620

cve-icon Vulnrichment

Updated: 2024-11-01T14:22:38.488Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-01T05:15:05.167

Modified: 2024-11-01T12:57:03.417

Link: CVE-2024-10620

cve-icon Redhat

No data.