CVE-2024-38175
published 2024-08-20CVE-2024-38175: An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.79%
51.5th percentile
An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_managed_instance_for_apache_cassandra | — | — |
| msrc | azure_managed_instance_for_apache_cassandra | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure Managed Instance for Apache Cassandra Elevation of Privilege Vulnerability
vendor_msrc·2024-08-13·CVSS 9.6
CVE-2024-38175 [CRITICAL] CWE-284 Azure Managed Instance for Apache Cassandra Elevation of Privilege Vulnerability
Azure Managed Instance for Apache Cassandra Elevation of Privilege Vulnerability
Description: An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H) and major loss of integrity (I:H) but have no effect on availability (A:N). What does that mean for this vulnerability?
Exploiting this vulnerability allows an attacker to view highly sensitive resource information (C:H) and results in a total loss of protection for that data (I:H), but does not provide the capability to impact resource availability.
FAQ: How could an attacker exploit this vulnerability?
GHSA
GHSA-4rcc-hgj8-2rw6: An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges ove
ghsa_unreviewed·2024-08-20
CVE-2024-38175 [CRITICAL] CWE-284 GHSA-4rcc-hgj8-2rw6: An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges ove
An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-20
Published