9.8
CVE-2024-2056
- EPSS 16.71%
- Veröffentlicht 05.03.2024 20:16:01
- Zuletzt bearbeitet 12.01.2026 15:44:02
- Quelle cve@takeonme.org
- CVE-Watchlists
- Unerledigt
Artica Proxy Loopback Services Remotely Accessible Unauthenticated
Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security issues associated with exposing this network service are documented at gvalkov's 'tailon' GitHub repo. Using the tailon service, the contents of any file on the Artica Proxy can be viewed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Articatech ≫ Artica Proxy Version4.50.000000 Update-
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 16.71% | 0.966 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-288 Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
http://seclists.org/fulldisclosure/2024/Mar/14
https://github.com/gvalkov/tailon#security
https://korelogic.com/Resources/Advisories/KL-001-2024-004.txt