made them vulnerable to attack by outside attackers with no
authentication.
No analysis available yet.
Vendor Solution
According to the researchers, the security gap in the FlyCASS online portal has been closed.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49148 | FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside attackers with no authentication. |
| Link | Providers |
|---|---|
| https://ian.sh/tsa |
|
Tue, 25 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Thu, 19 Sep 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flycass
Flycass flycass |
|
| CPEs | cpe:2.3:a:flycass:flycass:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Flycass
Flycass flycass |
Thu, 05 Sep 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Sep 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside attackers with no authentication. | |
| Title | FlyCASS Cockpit Access Security System (CASS) SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-11-25T14:22:09.394Z
Reserved: 2024-09-03T16:28:03.405Z
Link: CVE-2024-8395
Updated: 2024-09-05T20:28:14.335Z
Status : Analyzed
Published: 2024-09-05T20:15:05.743
Modified: 2024-09-19T17:53:45.753
Link: CVE-2024-8395
No data.
OpenCVE Enrichment
No data.
EUVD