authorized attacker to modify values outside those defined by their privileges (Elevation of Privileges) when the
attacker sends modified HTTPS requests to the device.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33140 | CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker to modify values outside those defined by their privileges (Elevation of Privileges) when the attacker sends modified HTTPS requests to the device. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 12 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Jan 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker to modify values outside those defined by their privileges (Elevation of Privileges) when the attacker sends modified HTTPS requests to the device. | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2025-02-12T16:50:20.155Z
Reserved: 2024-10-29T16:55:00.328Z
Link: CVE-2024-10497
Updated: 2025-02-12T16:50:15.431Z
Status : Received
Published: 2025-01-17T11:15:06.980
Modified: 2025-01-17T11:15:06.980
Link: CVE-2024-10497
No data.
OpenCVE Enrichment
No data.
EUVD