7.2

CVE-2024-1654

This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this. 
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PapercutPapercut Mf Version < 20.1.10
   ApplemacOS Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
PapercutPapercut Mf Version >= 21.0.0 < 21.2.14
   ApplemacOS Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
PapercutPapercut Mf Version >= 22.0.0 < 22.1.5
   ApplemacOS Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
PapercutPapercut Mf Version >= 23.0.1 < 23.0.7
   ApplemacOS Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
PapercutPapercut Ng Version < 20.1.10
   ApplemacOS Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
PapercutPapercut Ng Version >= 21.0.0 < 21.2.14
   ApplemacOS Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
PapercutPapercut Ng Version >= 22.0.0 < 22.1.5
   ApplemacOS Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
PapercutPapercut Ng Version >= 23.0.1 < 23.0.7
   ApplemacOS Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.51% 0.888
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
eb41dac7-0af8-4f84-9f6d-0272772514f4 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-183 Permissive List of Allowed Inputs

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.