CVE-2024-40404

CRITICAL

Cybele Software Thinfinity Workspace <7.0.2.113 - Privilege Escala...

Title source: llm
STIX 2.1

Description

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0044
EPSS Percentile 35.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
cybelesoft/thinfinity_workspace < 7.0.2.113
Published Nov 13, 2024
Tracked Since Feb 18, 2026