The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation.
Metrics
Affected Vendors & Products
References
History
Tue, 31 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 31 Dec 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation. | |
Title | Quanta Computer QOCA aim - Authorization Bypass | |
Weaknesses | CWE-639 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-12-31T01:35:20.576Z
Updated: 2024-12-31T15:54:48.243Z
Reserved: 2024-12-30T02:15:41.237Z
Link: CVE-2024-13040
Vulnrichment
Updated: 2024-12-31T15:54:43.138Z
NVD
Status : Received
Published: 2024-12-31T02:15:06.303
Modified: 2024-12-31T02:15:06.303
Link: CVE-2024-13040
Redhat
No data.