CVE-2024-10776

Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write files or load apps that use all features of the product available to a customer.
Configurations

No configuration.

History

06 Dec 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-06 13:15

Updated : 2024-12-06 13:15


NVD link : CVE-2024-10776

Mitre link : CVE-2024-10776

CVE.ORG link : CVE-2024-10776


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function