CVE-2024-23637
Last modified
CVE-2024-23637 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repeat their password. An attacker who managed to hijack an admin account might use this to lock out actual admins from their OctoPrint instance. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repeat their password. An attacker who managed to hijack an admin account might use this to lock out actual admins from their OctoPrint instance. The vulnerability will be patched in version 1.10.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Octoprint | Octoprint | <= 1.9.3 |
References
- https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-5626-pw9c-hmjrThird Party Advisory
- https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-5626-pw9c-hmjrThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-23637?
How severe is CVE-2024-23637?
How do I fix CVE-2024-23637?
Are you affected by CVE-2024-23637?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
