Vulnerability Description
The access control in CemiPark software does not properly validate user-entered data, which allows the authentication bypass. An attacker who has network access to the login panel can log in with administrator rights to the application.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- http://cemi.pl/
- https://cert.pl/en/posts/2024/05/CVE-2024-4423/
- https://cert.pl/posts/2024/05/CVE-2024-4423/
- http://cemi.pl/
- https://cert.pl/en/posts/2024/05/CVE-2024-4423/
- https://cert.pl/posts/2024/05/CVE-2024-4423/
FAQ
What is CVE-2024-4423?
CVE-2024-4423 is a vulnerability with a CVSS score of 7.2 (HIGH). The access control in CemiPark software does not properly validate user-entered data, which allows the authentication bypass. An attacker who has network access to the login panel can log in with admi...
How severe is CVE-2024-4423?
CVE-2024-4423 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-4423?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.