CVE-2024-3375: Broken Access Control in Havelsan's Dialogue
Published Apr 29, 2024
·Updated
Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Dialogue: from v1.83 before v1.83.1 or v1.84.
Affected Software
1 affected component
Havelsan Dialogue>=1.83<1.83.1, =1.84
Event History
Apr 29, 2024
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3375?
CVE-2024-3375 has a high severity due to incorrect permission assignments allowing unauthorized access.
2
How do I fix CVE-2024-3375?
To fix CVE-2024-3375, upgrade Havelsan Dialogue to version 1.83.1 or later.
3
What versions of Havelsan Dialogue are affected by CVE-2024-3375?
CVE-2024-3375 affects versions from 1.83 before 1.83.1 and version 1.84.
4
What are the consequences of exploiting CVE-2024-3375?
Exploitation of CVE-2024-3375 could allow an attacker to access functionalities not properly protected by access control lists.
5
Is there a workaround for CVE-2024-3375?
There are no known workarounds for CVE-2024-3375; updating to a fixed version is recommended.