CVE-2024-28345

An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly visit the URL.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sipwise:next_generation_communication_platform:*:*:*:*:-:*:*:*

History

17 Jun 2025, 17:08

Type Values Removed Values Added
References () https://securitycafe.ro/2024/03/21/cve-2024-28344-cve-2024-28345-in-sipwise-c5/ - () https://securitycafe.ro/2024/03/21/cve-2024-28344-cve-2024-28345-in-sipwise-c5/ - Exploit, Third Party Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:sipwise:next_generation_communication_platform:*:*:*:*:-:*:*:*
First Time Sipwise next Generation Communication Platform
Sipwise

06 Dec 2024, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

21 Nov 2024, 09:06

Type Values Removed Values Added
References () https://securitycafe.ro/2024/03/21/cve-2024-28344-cve-2024-28345-in-sipwise-c5/ - () https://securitycafe.ro/2024/03/21/cve-2024-28344-cve-2024-28345-in-sipwise-c5/ -
Summary
  • (es) Un problema descubierto en el panel de control de Sipwise C5 NGCP por debajo de mr11.5.1 permite que un usuario con pocos privilegios acceda al endpoint del diario visitando directamente la URL.

10 Apr 2024, 19:49

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-10 19:15

Updated : 2025-06-17 17:08


NVD link : CVE-2024-28345

Mitre link : CVE-2024-28345

CVE.ORG link : CVE-2024-28345


JSON object : View

Products Affected

sipwise

  • next_generation_communication_platform