Record summary

CVE-2024-50967 has a selected CVSS score of 6.5 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 27, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 17, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHub0xByteHunter/CVE-2024-50967Repository PoCby 0xByteHunterStars: 0Not analyzed2 files

1.4 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHDATAGERRY - Improper Access Control

The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.

Impact

Attackers can exploit this vulnerability to compromise system security and integrity.

Remediation

Apply the latest security patches and updates to address this vulnerability.

WeaknessesCWE-200
Authorss4e-io, 0xByteHunter
Template tagscvecve2024datagerryauth-bypassvkevvuln
Shodan: http.title:"datagerry"
FOFA: title="datagerry"
Google: intitle:"datagerry"

Source: ProjectDiscovery

References

4