Lucene search

K
cvelistM-Files CorporationCVELIST:CVE-2024-4056
HistoryApr 26, 2024 - 6:02 a.m.

CVE-2024-4056 Denial of service condition in M-Files Server

2024-04-2606:02:21
CWE-400
M-Files Corporation
www.cve.org
denial of service
m-files server
unauthenticated user
computing resources

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.1%

Denial of service condition in M-Files Server in versions before 24.4.13592.4Β and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "M-Files Server",
    "vendor": "M-Files Corporation",
    "versions": [
      {
        "lessThan": "24.4.13592.4",
        "status": "affected",
        "version": "23.11",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "24.2 LTS"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.1%

Related for CVELIST:CVE-2024-4056