← Back to browse · API

CVE-2024-2056

Severity
CRITICAL
CVSS
9.8
EPSS
0.16711
Risk score
45.05
CISA KEV
No
PoC
No
Published
2024-03-05
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2024-27021, GHSA-8JFC-89MC-PJWM
Products
Artica Tech:Artica Proxy, Artica Tech:Artica Proxy 4.50
Sources
euvd EUVD-2024-27021

Description

Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security issues associated with exposing this network service are documented at gvalkov's 'tailon' GitHub repo. Using the tailon service, the contents of any file on the Artica Proxy can be viewed.

References