CVE-2024-7015

Improper Authorization (CWE-285)

Published: Sep 9, 2024 / Updated: 2mo ago

010
CVSS 7.1EPSS 0.04%High
CVE info copied to clipboard

Improper Authentication, Missing Authentication for Critical Function, Improper Authorization vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse.This issue affects PassBox: before v1.2.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Timeline

CVE Assignment

NVD published the first details for CVE-2024-7015

Sep 9, 2024 at 2:15 PM
CVSS

A CVSS base score of 7.1 has been assigned.

Sep 9, 2024 at 2:20 PM / nvd
First Article

Feedly found the first article mentioning CVE-2024-7015. See article

Sep 9, 2024 at 2:21 PM / National Vulnerability Database
CVSS Estimate

Feedly estimated the CVSS score as HIGH

Sep 9, 2024 at 2:21 PM
EPSS

EPSS Score was set to: 0.04% (Percentile: 9.5%)

Sep 10, 2024 at 9:57 AM
Static CVE Timeline Graph

Affected Systems

Profelis/passbox
+null more

Links to Mitre Att&cks

T1574.010: Services File Permissions Weakness
+null more

Attack Patterns

CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
+null more

News

CVE-2024-7015
Improper Authentication, Missing Authentication for Critical Function, Improper Authorization vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse.This issue affects PassBox: before v1.2. CVE-2024-7015 originally published on CyberSecurityBoard
CVE-2024-7015
Critical Severity Description Improper Authentication, Missing Authentication for Critical Function, Improper Authorization vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse.This issue affects PassBox: before v1.2. Read more at https://www.tenable.com/cve/CVE-2024-7015
NA - CVE-2024-7015 - Improper Authentication, Missing Authentication...
Improper Authentication, Missing Authentication for Critical Function, Improper Authorization vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse.This issue...
CVE-2024-7015 Improper Authentication in Profelis Informatics and Consulting's PassBOX
Improper Authentication, Missing Authentication for Critical Function, Improper Authorization vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse.This issue affects PassBox: before...
CVE-2024-7015 | Profelis Informatics and Consulting PassBox up to 1.1 improper authentication
A vulnerability has been found in Profelis Informatics and Consulting PassBox up to 1.1 and classified as critical . Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authentication. This vulnerability is known as CVE-2024-7015 . The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
See 5 more articles and social media posts

CVSS V3.1

Attack Vector:Network
Attack Complexity:Low
Privileges Required:None
User Interaction:None
Scope:Unchanged
Confidentiality:High
Integrity:High
Availability Impact:High

Categories

Be the first to know about critical vulnerabilities

Collect, analyze, and share vulnerability reports faster using AI