Improper Access Control in ArcGIS Server by Esri
CVE-2024-51954

7.1HIGH

Key Information:

Vendor

Esri

Vendor
CVE Published:
3 March 2025

What is CVE-2024-51954?

An improper access control vulnerability exists in ArcGIS Server affecting versions 10.9.1 through 11.3 on both Windows and Linux. This vulnerability may allow a remote, low privileged authenticated attacker to gain unauthorized access to secure services published by a standalone ArcGIS Server instance under specific conditions. While this exploit raises significant concerns regarding data Confidentiality, its effects on integrity are minimal, and availability remains unaffected.

Affected Version(s)

ArcGIS Server Windows all <= 11.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-51954 : Improper Access Control in ArcGIS Server by Esri