CVE-2024-28058

HIGH

RSA NetWitness <12.5.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat actor could impersonate the revoked user and gain unauthorized access to sensitive data.

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 27.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-276
Status published
Published Nov 18, 2024
Tracked Since Feb 18, 2026