CVE-2024-23554: HCL BigFix Platform is susceptible to Cross-Site Request Forgery
Published May 17, 2024
·Updated
Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).
Affected Software
4 affected components
HCL BigFix Platform
hcltech Bigfix Platform>=9.5<9.5.25
hcltech Bigfix Platform>=10<10.0.12
hcltech Bigfix Platform=11.0.1
Event History
May 17, 2024
CVE Published
via MITRE·11:31 PM
Data Sourced
via MITRE·11:31 PM
DescriptionSeverityWeakness
May 18, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23554?
CVE-2024-23554 is classified as a high severity vulnerability due to its potential to cause Remote Code Execution.
2
How do I fix CVE-2024-23554?
To mitigate CVE-2024-23554, apply the latest security patches provided by HCL for the BigFix Platform.
3
What type of vulnerability is CVE-2024-23554?
CVE-2024-23554 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to Remote Code Execution.
4
Who is affected by CVE-2024-23554?
CVE-2024-23554 affects users of the HCL BigFix Platform.
5
What are the potential impacts of CVE-2024-23554?
Exploitation of CVE-2024-23554 could allow attackers to execute arbitrary code on affected systems.