CVE-2024-2055
Artica Proxy Unauthenticated File Manager Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.
La función "Rich Filemanager" de Artica Proxy proporciona una interfaz basada en web para capacidades de administración de archivos. Cuando la función está habilitada, no requiere autenticación de forma predeterminada y se ejecuta como usuario raíz.
The Rich Filemanager feature of Artica Proxy versions 4.40 and 4.50 provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user. This provides an unauthenticated attacker complete access to the file system.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-03-01 CVE Reserved
- 2024-03-05 CVE Published
- 2024-03-06 EPSS Updated
- 2024-08-26 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-288: Authentication Bypass Using an Alternate Path or Channel
- CWE-552: Files or Directories Accessible to External Parties
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2024/Mar/13 | ||
https://korelogic.com/Resources/Advisories/KL-001-2024-003.txt | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Artica Tech Search vendor "Artica Tech" | Artica Proxy Search vendor "Artica Tech" for product "Artica Proxy" | 4.50 Search vendor "Artica Tech" for product "Artica Proxy" and version "4.50" | en |
Affected
| ||||||
Artica Tech Search vendor "Artica Tech" | Artica Proxy Search vendor "Artica Tech" for product "Artica Proxy" | 4.40 Search vendor "Artica Tech" for product "Artica Proxy" and version "4.40" | en |
Affected
|