ZeroHour

CVE-2024-11482

PoC
CVSS 3.1
9.8 critical
EPSS
3%p84
Published
()
Modified
Description

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.

Vendors
trellix
Products
enterprise security manager
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.