CVE CVE

CVE-2024-4358

CISA Known Exploited Vulnerability (KEV)

Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

June 13, 2024

July 4, 2024

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

Weakness Enumeration

CWE-ID CWE Name

CWE-290
Authentication Bypass by Spoofing

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
9.8
Severity:

CRITICAL

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2

Not defined