Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-48939

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Paxton Access Net2是Paxton Access公司的一款应用程序,提供简单灵活的站点管理。 Paxton Access Net2 6.07.14023.5015 (SR4)之前版本存在安全漏洞,该漏洞源于对REST API许可证文件执行的验证不足,导致可以通过无效许可证文件来使用REST API,攻击者能够检索访问日志数据。

AI Predicted 7.5 Difficulty: Easy EPSS 0.71% · P51

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-48939

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Insufficient validation performed on the REST API License file in Paxton Net2 before 6.07.14023.5015 (SR4) enables use of the REST API with an invalid License File. Attackers may be able to retrieve access-log data.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Paxton Access Net2 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Paxton Access Net2是Paxton Access公司的一款应用程序,提供简单灵活的站点管理。 Paxton Access Net2 6.07.14023.5015 (SR4)之前版本存在安全漏洞,该漏洞源于对REST API许可证文件执行的验证不足,导致可以通过无效许可证文件来使用REST API,攻击者能够检索访问日志数据。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2024-48939

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-48939

登录查看更多情报信息。

Vendor Pages for CVE-2024-48939 (1)

Same Patch Batch · n/a · 2024-11-11 · 31 CVEs total

CVE-2024-25255 Sublime Text 安全漏洞
CVE-2024-52530 libsoup 安全漏洞
CVE-2024-52532 libsoup 安全漏洞
CVE-2024-52533 GNOME GLib 安全漏洞
CVE-2024-36061 EnGenius EWS356-FIT 安全漏洞
CVE-2024-50636 PyMOL 安全漏洞
CVE-2024-50667 Trendnet TEW-820AP 安全漏洞
CVE-2024-50601 Axigen Mail Server 安全漏洞
CVE-2024-46963 Super Unlimited com.superfast.video.downloader 安全漏洞
CVE-2024-46965 DS Browsers allvideo.downloader.browser 安全漏洞
CVE-2024-46966 Ikhgur mn.ikhgur.khotoch 安全漏洞
CVE-2024-46962 SYQ com.downloader.video.fast 安全漏洞
CVE-2024-46964 Video Developers com.video.downloader.all 安全漏洞
CVE-2024-25253 IObit Driver Booster 安全漏洞
CVE-2024-25254 Foundstone SuperScan 安全漏洞
CVE-2024-51054 PHPGurukul Online Marriage Registration System 安全漏洞
CVE-2024-48322 run.codes 安全漏洞
CVE-2024-44546 PowerJob 安全漏洞
CVE-2024-51188 TRENDnet TEW-651BR 安全漏洞
CVE-2024-51187 TRENDnet TEW-651BR 安全漏洞

Showing top 20 of 31 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2024-48939

No comments yet


Leave a comment