CVE-2024-2054: Artica Proxy Unauthenticated PHP Deserialization Vulnerability
Published Mar 5, 2024
·Updated
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
Affected Software
2 affected components
Artica Artica Proxy
Articatech Artica Proxy=4.50.000000
Event History
Mar 5, 2024
CVE Published
via MITRE·06:56 PM
Data Sourced
via MITRE·06:56 PM
DescriptionWeakness
Mar 21, 2024
Data Sourced
via NVD·02:52 AM
DescriptionSeverityWeaknessAffected Software
Apr 9, 2025
Exploit Published
12:00 AM
Known Exploited
09:48 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-2054?
CVE-2024-2054 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-2054?
To fix CVE-2024-2054, update your Artica Proxy installation to the latest version provided by the vendor.
3
What type of attack does CVE-2024-2054 facilitate?
CVE-2024-2054 facilitates remote code execution attacks through insecure deserialization of PHP objects.
4
Who is affected by CVE-2024-2054?
CVE-2024-2054 affects users of the Artica-Proxy administrative web application if they are running vulnerable versions.
5
Can CVE-2024-2054 be exploited without authentication?
Yes, CVE-2024-2054 can be exploited by unauthenticated users, making it particularly dangerous.