Lucene search

K
nvdF86ef6dc-4d3a-42ad-8f28-e6d5547a5007NVD:CVE-2024-3116
HistoryApr 04, 2024 - 3:15 p.m.

CVE-2024-3116

2024-04-0415:15:39
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
web.nvd.nist.gov
1
pgadmin
vulnerability
cve-2024-3116
rce
remote code execution
server security
data integrity

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

EPSS

0.003

Percentile

65.8%

pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system’s integrity and the security of the underlying data.

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

EPSS

0.003

Percentile

65.8%