Vulnerability Description
An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly visit the URL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sipwise | Next Generation Communication Platform | < mr11.5.1 |
References
- https://securitycafe.ro/2024/03/21/cve-2024-28344-cve-2024-28345-in-sipwise-c5/ExploitThird Party Advisory
- https://securitycafe.ro/2024/03/21/cve-2024-28344-cve-2024-28345-in-sipwise-c5/ExploitThird Party Advisory
FAQ
What is CVE-2024-28345?
CVE-2024-28345 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly visit the URL.
How severe is CVE-2024-28345?
CVE-2024-28345 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28345?
Check the references section above for vendor advisories and patch information. Affected products include: Sipwise Next Generation Communication Platform.