CVE Vulnerabilities

CVE-2024-43692

Authentication Bypass Using an Alternate Path or Channel

Published: Sep 25, 2024 | Modified: Oct 01, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Progauge_maglink_lx_console_firmware Doverfuelingsolutions * 3.4.2.2.6 (including)

Potential Mitigations

References