CVE-2024-45871

Improper Input Validation (CWE-20)

Published: Oct 3, 2024 / Updated: 47d ago

010
CVSS 6.3EPSS 0.04%Medium
CVE info copied to clipboard

Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Timeline

CVE Assignment

NVD published the first details for CVE-2024-45871

Oct 3, 2024 at 5:15 PM
First Article

Feedly found the first article mentioning CVE-2024-45871. See article

Oct 3, 2024 at 5:22 PM / Vulners.com RSS Feed
CVSS Estimate

Feedly estimated the CVSS score as MEDIUM

Oct 3, 2024 at 5:38 PM
CVSS

A CVSS base score of 6.3 has been assigned.

Oct 3, 2024 at 8:41 PM / nvd
EPSS

EPSS Score was set to: 0.04% (Percentile: 9.6%)

Oct 4, 2024 at 9:41 AM
Static CVE Timeline Graph

Affected Systems

Bandisoft
+null more

Links to Mitre Att&cks

T1562.003: Impair Command History Logging
+null more

Attack Patterns

CAPEC-10: Buffer Overflow via Environment Variables
+null more

CVSS V3.1

Attack Vector:Adjacent_network
Attack Complexity:Low
Privileges Required:None
User Interaction:None
Scope:Unchanged
Confidentiality:Low
Integrity:Low
Availability Impact:Low

Categories

Be the first to know about critical vulnerabilities

Collect, analyze, and share vulnerability reports faster using AI