CVE-2024-28140
Last modified
CVE-2024-28140 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user. This can be confirmed by running "ps aux" as the root user and observing the output.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-28140?
How severe is CVE-2024-28140?
How do I fix CVE-2024-28140?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-28135A low privileged remote attacker can use a command injection…5
- CVE-2024-28136A local attacker with low privileges can use a command injec…7.8
- CVE-2024-28137 …7.8
- CVE-2024-28138An unauthenticated attacker with network access to the affec…7.3
- CVE-2024-28139The www-data user can elevate its privileges because sudo is…8.8
- CVE-2024-2814A vulnerability was found in Tenda AC15 15.03.20_multi. It h…9.8
- CVE-2024-28141The web application is not protected against cross-site requ…6.3
- CVE-2024-28142Due to missing input sanitization, an attacker can perform c…4.7
- CVE-2024-28143The password change function at /cgi/admin.cgi does not requ…8.4
- CVE-2024-28144An attacker who can spoof the IP address and the User-Agent …5.5
- CVE-2024-28145An unauthenticated attacker can perform an SQL injection by …5.9
- CVE-2024-28146The application uses several hard-coded credentials to encry…8.4
Are you affected by CVE-2024-28140?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
