9.8
CVE-2024-2055
- EPSS 0.07%
- Veröffentlicht 05.03.2024 20:16:01
- Zuletzt bearbeitet 12.01.2026 15:45:51
- Quelle cve@takeonme.org
- CVE-Watchlists
- Unerledigt
The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Articatech ≫ Artica Proxy Version4.40.000000
Articatech ≫ Artica Proxy Version4.50.000000
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.211 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-288 Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.