CVE-2024-36248

Published Nov 26, 2024

Last updated 3 months ago

Overview

Description
API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
Source
vultures@jpcert.or.jp
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

vultures@jpcert.or.jp
CWE-798

Social media

Hype score
Not currently trending