CVE Vulnerabilities

CVE-2024-33610

Authentication Bypass Using an Alternate Path or Channel

Published: Nov 26, 2024 | Modified: Nov 26, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

sessionlist.html and sys_trayentryreboot.html are accessible with no authentication. sessionlist.html provides logged-in users session information including session cookies, and sys_trayentryreboot.html allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Potential Mitigations

References