CVE-2024-34640
published 2024-09-04CVE-2024-34640: Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
PriorityP410low3.3CVSS 3.1
AVLACLPRLUINSUCNILAN
EPSS
0.14%
3.7th percentile
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mantisbt | mantisbt | >= 0 < 2.26.4 | 2.26.4 |
| samsung | android | — | — |
| samsung | android | — | — |
| samsung | android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
MantisBT vulnerable to information disclosure with user profiles
ghsa·2024-09-30
CVE-2024-45792 [MEDIUM] CWE-200 MantisBT vulnerable to information disclosure with user profiles
MantisBT vulnerable to information disclosure with user profiles
Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles.
### Impact
Disclosure of private system profiles: Platform, OS, OS version, Description.
### Patches
- https://github.com/mantisbt/mantisbt/commit/56bbd02dc1fb33a8de5898fd17dc3d698c847f55
### Workarounds
None
### References
https://mantisbt.org/bugs/view.php?id=34640
GHSA
GHSA-c826-p37x-6qgw: Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expi
ghsa_unreviewed·2024-09-04
CVE-2024-34640 [LOW] GHSA-c826-p37x-6qgw: Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expi
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-04
Published