nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-39755 CVE-2024-39755
HIGH
Record summary
CVE-2024-39755 has a selected CVSS score of 7.8 (high).
Description
A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 3, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Anka BuildBrowse Veertu / Anka BuildDefault status: unknown | CVE List | 1.42.0 | affected |
References
3talosintelligence.com
https://talosintelligence.com/vulnerability_reports/TALOS-2024-2060 talosintelligence.com
https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2060