← Back to browse · API

CVE-2024-42017

Severity
CRITICAL
CVSS
10.0
EPSS
0.00547
Risk score
40.19
CISA KEV
No
PoC
No
Published
2024-09-30
Modified
2024-10-29
First seen
2026-08-07
Aliases
EUVD-2024-39394, GHSA-HJPG-CFQW-G6JV
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-39394

Description

An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an attacker to execute arbitrary commands with system privilege on the endpoint hosting the application, without any authentication.

References