CVE-2024-46310
CRITICALCVSS 9.1/10EPSS 2.39%
Last modified
CVE-2024-46310 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint. EPSS estimates a 2.39% chance of exploitation in the next 30 days.
Description
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-46310?
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint
How severe is CVE-2024-46310?
CVE-2024-46310 has a CVSS score of 9.1/10 (CRITICAL severity). The EPSS model estimates a 2.39% probability of exploitation in the next 30 days.
How do I fix CVE-2024-46310?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-46293Sourcecodester Online Medicine Ordering System 1.0 is vulner…9.8
- CVE-2024-4630The Starter Templates — Elementor, WordPress & Beaver Builde…6.4
- CVE-2024-46300itsourcecode Placement Management System 1.0 is vulnerable t…6.1
- CVE-2024-46304A NULL pointer dereference in libcoap v4.3.5-rc2 and below a…7.5
- CVE-2024-46307A loop hole in the payment logic of Sparkshop v1.16 allows a…7.5
- CVE-2024-4631Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2024-46313TP-Link WR941ND V6 has a stack overflow vulnerability in the…8
- CVE-2024-46316DrayTek Vigor3900 v1.5.1.6 was discovered to contain a comma…8
- CVE-2024-4632The WooCommerce Checkout & Funnel Builder by CartFlows – Cre…6.4
- CVE-2024-46325TP-Link WR740N V6 has a stack overflow vulnerability via the…5.5
- CVE-2024-46326Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vuln…6.1
- CVE-2024-46327An issue in the Http_handle object of VONETS VAP11G-300 v3.3…5.7
Are you affected by CVE-2024-46310?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
