Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-51954

Опубликовано: 03 мар. 2025
Источник: nvd
CVSS3: 8.5
EPSS Низкий

Описание

There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfederated) ArcGIS Server instance. Successful exploitation results in unauthorized access to protected services outside the attacker’s originally assigned authorization boundary, constituting a scope change. If exploited, this issue would have a high impact on confidentiality, a low impact on integrity, and no impact on the availability of the software.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*
Версия от 10.9.1 (включая) до 11.3 (включая)

Одно из

cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 24%
0.00309
Низкий

8.5 High

CVSS3

Дефекты

CWE-284
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.5
github
больше 1 года назад

There is an improper access control issue in ArcGIS Server versions 10.9.1 through 11.3 on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standalone (Unfederated) ArcGIS Server instance.  If successful this compromise would have a high impact on Confidentiality, low impact on integrity and no impact to availability of the software.

CVSS3: 8.5
fstec
больше 1 года назад

Уязвимость сервера ArcGIS Server, связанная с недостатками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 24%
0.00309
Низкий

8.5 High

CVSS3

Дефекты

CWE-284
NVD-CWE-noinfo