Skip to content
COOEY

EXPOSURES › CVE-2024-4358

CVE-2024-4358

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-06-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-4358 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildauth-bypassunpatched

Progress Telerik Report Server allows attackers to bypass authentication via spoofing, enabling unauthorized access to report generation features.

This vulnerability permits attackers to spoof authentication tokens to access unauthorized reports, creating a significant risk for DIB organizations relying on Progress Telerik Report Server for secure data handling. The exploitability of this bypass means it could lead to data exfiltration or ransomware entry if combined with other vulnerabilities, necessitating immediate vendor patching and internal access control reviews.

Shame score — The vulnerability allows authentication bypass but lacks evidence of remote code execution or zero-day exploitation, resulting in moderate embarrassment.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.