CVE Vulnerabilities

CVE-2024-45373

Improper Privilege Management

Published: Sep 25, 2024 | Modified: Oct 01, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Progauge_maglink_lx_console_firmware Doverfuelingsolutions * 3.4.2.2.6 (including)

Potential Mitigations

References