CVE Vulnerabilities

CVE-2024-43692

Authentication Bypass Using an Alternate Path or Channel

Published: Sep 25, 2024 | Modified: Oct 01, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
Progauge_maglink_lx_console_firmwareDoverfuelingsolutions*3.4.2.2.6 (including)

Potential Mitigations

References