MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other users' credential and sensitive information may be retrieved.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-41596 MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other users' credential and sensitive information may be retrieved.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00109}

epss

{'score': 0.0011}


Wed, 06 Nov 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Neumann
Neumann musasi
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:neumann:musasi:3:*:*:*:*:*:*:*
Vendors & Products Neumann
Neumann musasi
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Fri, 25 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Neumannjp
Neumannjp musasi
CPEs cpe:2.3:a:neumannjp:musasi:*:*:*:*:*:*:*:*
Vendors & Products Neumannjp
Neumannjp musasi
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Oct 2024 08:00:00 +0000

Type Values Removed Values Added
Description MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other users' credential and sensitive information may be retrieved.
Weaknesses CWE-603
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-10-25T14:04:55.715Z

Reserved: 2024-09-09T06:15:53.127Z

Link: CVE-2024-45785

cve-icon Vulnrichment

Updated: 2024-10-25T14:04:37.435Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-25T08:15:02.883

Modified: 2024-11-06T17:08:40.507

Link: CVE-2024-45785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.