Vulnerability Description
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cs-Technologies | Evolution | <= 2.04.560 |
Related Weaknesses (CWE)
References
- https://directcyber.com.au/sa/CVE-2024-29836-to-29844-evolution-controller-multiThird Party Advisory
- https://directcyber.com.au/sa/CVE-2024-29836-to-29844-evolution-controller-multiThird Party Advisory
FAQ
What is CVE-2024-29839?
CVE-2024-29839 is a vulnerability with a CVSS score of 7.5 (HIGH). The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to re...
How severe is CVE-2024-29839?
CVE-2024-29839 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-29839?
Check the references section above for vendor advisories and patch information. Affected products include: Cs-Technologies Evolution.