CVE-2024-2055

CRITICAL

Artica Proxy - Privilege Escalation

Title source: llm
STIX 2.1

Description

The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.

Scores

CVSS v3 9.8
EPSS 0.0007
EPSS Percentile 20.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-552 CWE-288
Status published
Products (2)
articatech/artica_proxy 4.40.000000
articatech/artica_proxy 4.50.000000
Published Mar 05, 2024
Tracked Since Feb 18, 2026