Vulnerability Description
4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 4Ipnet | Eap-767 Firmware | 3.42.00 |
| 4Ipnet | Eap-767 | All versions |
Related Weaknesses (CWE)
References
- https://github.com/yckuo-sdc/PoCExploitThird Party Advisory
- https://github.com/yckuo-sdc/PoCExploitThird Party Advisory
FAQ
What is CVE-2024-24300?
CVE-2024-24300 is a vulnerability with a CVSS score of 9.8 (CRITICAL). 4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged...
How severe is CVE-2024-24300?
CVE-2024-24300 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-24300?
Check the references section above for vendor advisories and patch information. Affected products include: 4Ipnet Eap-767 Firmware, 4Ipnet Eap-767.