CVE-2024-48939

HIGH

Paxton Net2 <6.07.14023.5015 - Info Disclosure

Title source: llm
STIX 2.1

Description

Insufficient validation performed on the REST API License file in Paxton Net2 before 6.07.14023.5015 (SR4) enables use of the REST API with an invalid License File. Attackers may be able to retrieve access-log data.

Scores

CVSS v3 7.5
EPSS 0.0040
EPSS Percentile 60.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-922
Status published
Published Nov 11, 2024
Tracked Since Feb 18, 2026