CVE Vulnerabilities

CVE-2024-45373

Improper Privilege Management

Published: Sep 25, 2024 | Modified: Oct 01, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Progauge_maglink_lx_console_firmwareDoverfuelingsolutions*3.4.2.2.6 (including)

Potential Mitigations

References