Difficult to Exploit Authentication Issue Affects ArcGIS Software
CVE-2024-25699
8.1HIGH
What is CVE-2024-25699?
The Home application of Esri's Portal for ArcGIS exhibits an improper authentication vulnerability affecting both Windows and Linux platforms. This flaw could be exploited under specific conditions, allowing remote, unauthenticated attackers to potentially compromise the software's confidentiality, integrity, and availability. Affected versions range from 10.8.1 through 11.2 for the Portal on desktop systems and ArcGIS Enterprise 11.1 and earlier on Kubernetes. Organizations using these versions should prioritize the implementation of necessary security updates to mitigate potential threats.
Affected Version(s)
Portal for ArcGIS Windows all
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published