An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that it is possible for any user (with any privilege) of Audimex to dump the whole Audimex database. This gives visibility upon password hashes of any user, ongoing audit data and more.
History

Fri, 22 Nov 2024 16:30:00 +0000

Type Values Removed Values Added
Description An issue in Audimex EE v.15.1.20 and before allows a remote attacker to escalate privileges. An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that it is possible for any user (with any privilege) of Audimex to dump the whole Audimex database. This gives visibility upon password hashes of any user, ongoing audit data and more.

Thu, 21 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Audimex
Audimex audimexee
Weaknesses CWE-276
CPEs cpe:2.3:a:audimex:audimexee:*:*:*:*:*:*:*:*
Vendors & Products Audimex
Audimex audimexee
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 20 Nov 2024 16:45:00 +0000

Type Values Removed Values Added
Description An issue in Audimex EE v.15.1.20 and before allows a remote attacker to escalate privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-20T00:00:00

Updated: 2024-11-22T16:15:34.901781

Reserved: 2024-10-28T00:00:00

Link: CVE-2024-51162

cve-icon Vulnrichment

Updated: 2024-11-21T15:45:01.573Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-20T17:15:18.120

Modified: 2024-11-22T17:15:09.353

Link: CVE-2024-51162

cve-icon Redhat

No data.