Business Logic Flaw in Infoblox BloxOne Affects Multiple Users
CVE-2024-46505

9.1CRITICAL

Key Information:

Vendor

Infoblox

Vendor
CVE Published:
9 January 2025

What is CVE-2024-46505?

Infoblox BloxOne v2.4 has been identified with a business logic flaw stemming from vulnerabilities in its thick client architecture. This issue can potentially allow unauthorized actions by exploiting the inherent weaknesses in the application logic, leading to unintended consequences and security concerns for users.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.