CVE-2024-2055

CRITICAL

Artica Proxy - Privilege Escalation

Title source: llm
STIX 2.1

Description

The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory, Exploit
http://seclists.org/fulldisclosure/2024/Mar/13
Third Party Advisory, Exploit third-party-advisory
https://korelogic.com/Resources/Advisories/KL-001-2024-003.txt

Scores

CVSS v3 9.8
EPSS 0.0093
EPSS Percentile 55.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-552 CWE-288
Status published
Products (2)
articatech/artica_proxy 4.40.000000
articatech/artica_proxy 4.50.000000
Published Mar 05, 2024
Tracked Since Feb 18, 2026