CVE-2024-23815

A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of a highly protected zone), Desigo CC (All versions if access from Installed Clients to Desigo CC server is only allowed within highly protected zones). The affected server application fails to authenticate specific client requests. Modification of the client binary could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database via the event port (default: 4998/tcp)
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en Desigo CC (todas las versiones si se permite el acceso desde clientes instalados al servidor de Desigo CC desde redes fuera de una zona de alta protección). La aplicación de servidor afectada no autentica solicitudes específicas del cliente. La modificación del binario del cliente podría permitir que un atacante remoto no autenticado ejecute consultas SQL arbitrarias en la base de datos del servidor a través del puerto de eventos (predeterminado: 4998/tcp).

13 May 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-13 10:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-23815

Mitre link : CVE-2024-23815

CVE.ORG link : CVE-2024-23815


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function