Privilege Escalation Flaw in Atos Eviden IDRA
CVE-2024-51505

8HIGH

Key Information:

Vendor

Atos

Vendor
CVE Published:
18 February 2025

What is CVE-2024-51505?

A vulnerability exists in Atos Eviden IDRA prior to version 2.7.1, allowing a highly trusted role, specifically Config Admin, to exploit a race condition. This could result in unintended privilege escalation, enabling unauthorized actions within the system.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.