← Back to browse · API

CVE-2024-11482

Severity
CRITICAL
CVSS
9.8
EPSS
0.02544
Risk score
40.09
CISA KEV
No
PoC
No
Published
2024-11-29
Modified
2025-03-18
First seen
2026-08-07
Aliases
EUVD-2024-34063, GHSA-WHHW-2V2C-QG98
Products
Trellix:Trellix Enterprise Security Manager (ESM) 11.6.12
Sources
euvd EUVD-2024-34063

Description

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.

References