CVE-2024-2055: Artica Proxy Unauthenticated File Manager Vulnerability
Published Mar 5, 2024
·Updated
The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.
Affected Software
3 affected components
Artica Proxy
Articatech Artica Proxy=4.40.000000
Articatech Artica Proxy=4.50.000000
Event History
Mar 5, 2024
CVE Published
via MITRE·06:56 PM
Data Sourced
via MITRE·06:56 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-2055?
CVE-2024-2055 is considered a critical vulnerability due to the lack of authentication and running as the root user.
2
How do I fix CVE-2024-2055?
To fix CVE-2024-2055, disable the Rich Filemanager feature or implement proper authentication controls.
3
What software is affected by CVE-2024-2055?
CVE-2024-2055 affects the Artica Proxy software when the Rich Filemanager feature is enabled.
4
Can CVE-2024-2055 be exploited remotely?
Yes, CVE-2024-2055 can be exploited remotely due to the absence of authentication.
5
What actions should be taken to mitigate risks from CVE-2024-2055?
To mitigate risks from CVE-2024-2055, ensure that the Rich Filemanager feature is disabled if not in use and review user permissions.