TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2024-5671

CRITICAL
9.8

Beschreibung

Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS Manager.

CVE Details

CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht6/14/2024
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Schwachen (CWE)

CWE-502

Referenzen

https://thrive.trellix.com/s/article/000013623(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.