Vulnerability Description
Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, from 7.4.1 before 7.4.9, from 7.3.1 before 7.3.18.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sigb | Pmb | >= 7.3.1, < 7.3.18 |
Related Weaknesses (CWE)
References
- https://forge.sigb.net/projects/pmb/filesProduct
- https://github.com/enisaeu/CNW/blob/main/advisories/2024/CNW-2024-A-12.mdThird Party Advisory
- https://forge.sigb.net/projects/pmb/filesProduct
- https://github.com/enisaeu/CNW/blob/main/advisories/2024/CNW-2024-A-12.mdThird Party Advisory
FAQ
What is CVE-2024-26289?
CVE-2024-26289 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, from 7.4.1 before 7.4.9, from 7.3.1 before 7.3.18.
How severe is CVE-2024-26289?
CVE-2024-26289 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-26289?
Check the references section above for vendor advisories and patch information. Affected products include: Sigb Pmb.