CVE-2024-5514

CRITICAL

MinMax CMS - Auth Bypass

Title source: llm
STIX 2.1

Description

MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend system without being recorded in the system logs.

Scores

CVSS v3 9.8
EPSS 0.0023
EPSS Percentile 46.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-798 CWE-912
Status published
Products (1)
MinMax Digital Technology/MinMax CMS
Published May 30, 2024
Tracked Since Feb 18, 2026