CVE-2024-5168

CRITICAL

Prodys' Quantum Audio codec <2.3.4t - Auth Bypass

Title source: llm
STIX 2.1

Description

Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely and execute arbitrary API requests against the web application.

Scores

CVSS v3 9.8
EPSS 0.0053
EPSS Percentile 40.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
Prodys/Quantum Audio codec 2.3.4t
Published May 23, 2024
Tracked Since Feb 18, 2026