5.7

CVE-2024-23554

Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE). 

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Vendorhcltech
Product bigfix_platform
Default Statusunaffected
Version <= 9.5.24
Version 9.5
Status affected
Vendorhcltech
Product bigfix_platform
Default Statusunaffected
Version <= 10.0.11
Version 10.0.0
Status affected
Vendorhcltech
Product bigfix_platform
Default Statusunaffected
Version 11.0.1
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.24% 0.465
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
psirt@hcl.com 5.7 0.5 5.2
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.