CVE Vulnerabilities

CVE-2024-12136

Missing Critical Step in Authentication

Published: Mar 19, 2025 | Modified: May 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass.This issue affects ANKA JPD-00028: through 19.03.2025.

NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE will be updated when new information becomes available.

Weakness

The product implements an authentication technique, but it skips a step that weakens the technique.

Affected Software

Name Vendor Start Version End Version
Anka_jpd00028_firmware Elfatek - (including) - (including)

References