CVE-2024-9984
Ragic Enterprise Cloud Database - Missing Authentication
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
15 Oct 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Ragic · Enterprise Cloud DatabaseWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →