CVE-2024-57055

Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue is limited to services used by the client (not the general-use JSON services) and requires reverse engineering of the proprietary serialization protocol, making it difficult to exploit.
Configurations

No configuration.

History

19 Feb 2025, 21:15

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de Server-Side Access Control Bypass en WombatDialer antes de 25.02 podría permitir a los usuarios no autorizados llamar potencialmente ciertos servicios sin el nivel de acceso necesario. Este problema se limita a los servicios utilizados por el cliente (no los servicios JSON de uso general) y requiere ingeniería inversa del protocolo de serialización patentado, lo que dificulta la explotación.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.0
CWE CWE-306

18 Feb 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-18 19:15

Updated : 2025-02-19 21:15


NVD link : CVE-2024-57055

Mitre link : CVE-2024-57055

CVE.ORG link : CVE-2024-57055


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function