ZeroHour

CVE-2024-27168

CVSS 3.1
7.1 high
EPSS
<1%p21
Published
()
Modified
Description

It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the affected products/models/versions, see the reference URL.

Weakness
CWE-798
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.