Lucene search

K
cve[email protected]CVE-2024-3995
HistoryJun 28, 2024 - 8:15 p.m.

CVE-2024-3995

2024-06-2820:15:02
web.nvd.nist.gov
11
cve-2024-3995
helix alm
command injection
bryan riggins

2 Low

CVSS4

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/SC:N/VI:L/SI:N/VA:L/SA:N

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Helix ALM",
    "vendor": "Perforce",
    "versions": [
      {
        "lessThan": "2024.2.0 (CVE-2024-3995 Patch)",
        "status": "affected",
        "version": "2024.2.0",
        "versionType": "semver"
      }
    ]
  }
]

2 Low

CVSS4

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/SC:N/VI:L/SI:N/VA:L/SA:N

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2024-3995