Missing Authorization Vulnerability Affects Hercules Core
CVE-2024-37232
8.8HIGH
Summary
The Hercules Core product from Hercules Design has a vulnerability arising from missing authorization checks that impact the access control mechanisms. This issue may allow malicious users to exploit incorrectly configured security levels, enabling unauthorized changes and access to restricted functionalities. Versions of Hercules Core from n/a to 6.5 are specifically impacted, highlighting the importance of proper configuration and ongoing monitoring to safeguard against potential exploitation.
Affected Version(s)
Hercules Core <= 6.5
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dave Jong (Patchstack)