CVE-2024-39328: Medium severity atos eviden idra vulnerability
Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their configuration privileges in a multi-partition environment and access some confidential data. Data integrity and availability is not at risk.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39328?
CVE-2024-39328 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2024-39328?
To fix CVE-2024-39328, upgrade Atos Eviden IDRA and IDCA to version 2.7.0 or later.
What type of vulnerability is CVE-2024-39328?
CVE-2024-39328 is an insecure permissions vulnerability affecting the Config Admin role in a multi-partition environment.
What are the potential impacts of CVE-2024-39328?
The potential impact of CVE-2024-39328 includes the unauthorized access to confidential data, though data integrity and availability remain intact.
Which products are affected by CVE-2024-39328?
CVE-2024-39328 affects Atos Eviden IDRA and IDCA versions prior to 2.7.0.