8.8
CVE-2024-2975
- EPSS 0.41%
- Veröffentlicht 09.04.2024 01:15:49
- Zuletzt bearbeitet 02.07.2025 12:32:30
- Quelle security@octopus.com
- CVE-Watchlists
- Unerledigt
A race condition was identified through which privilege escalation was possible in certain configurations.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Octopus ≫ Octopus Server Version >= 0.9 < 2023.4.8432
Octopus ≫ Octopus Server Version >= 2024.1.437 < 2024.1.12087
Octopus ≫ Octopus Server Version >= 2024.2.101 < 2024.2.2075
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.604 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| security@octopus.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-1223 Race Condition for Write-Once Attributes
A write-once register in hardware design is programmable by an untrusted software component earlier than the trusted software component, resulting in a race condition issue.