Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely and execute arbitrary API requests against the web application.
Metrics
Affected Vendors & Products
Fixes
Solution
The vendor attempted to fix the vulnerability in version 2.3.4t, limiting exploitation to a low-privileged attacker only. Finally, the vulnerability was fully fixed by the manufacturer in version 2.3.4w.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T21:03:10.998Z
Reserved: 2024-05-21T11:32:15.379Z
Link: CVE-2024-5168

Updated: 2024-08-01T21:03:10.998Z

Status : Awaiting Analysis
Published: 2024-05-23T13:15:09.810
Modified: 2024-11-21T09:47:06.987
Link: CVE-2024-5168

No data.

No data.