ZeroHour

CVE-2024-8779

CVSS 3.1
8.8 high
EPSS
<1%p44
Published
()
Modified
Description

OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowing remote attackers with regular privileges to update system settings or create accounts with administrator privileges, thereby gaining control of the server.

Vendors
syscomgo
Products
omflow
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.