Incorrect Access Control in Jamf Private Access
CVE-2022-29564

7.5HIGH

Key Information:

Vendor

Jamf

Vendor
CVE Published:
7 June 2022

What is CVE-2022-29564?

Jamf Private Access prior to May 16, 2022, exhibits a flaw in its access control mechanism, allowing unauthorized users to potentially access sensitive systems within the internal network. This security gap could lead to unauthorized exposure of critical infrastructure, emphasizing the need for users to update their systems promptly to safeguard against possible intrusions.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.