CVE-2024-4220: Information Disclosure in BeyondInsight
Published Jun 4, 2024
·Updated
Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.
Affected Software
1 affected component
BeyondTrust Beyondinsight<23.1
Event History
Jun 4, 2024
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-4220?
CVE-2024-4220 has a medium severity level due to the potential for information disclosure.
2
What does CVE-2024-4220 affect?
CVE-2024-4220 affects versions of BeyondInsight prior to 23.1.
3
How do I fix CVE-2024-4220?
The recommended fix for CVE-2024-4220 is to upgrade BeyondInsight to version 23.1 or later.
4
What type of vulnerability is CVE-2024-4220?
CVE-2024-4220 is classified as an information disclosure vulnerability.
5
What can an attacker do with CVE-2024-4220?
An attacker can potentially enumerate usernames due to the vulnerability in CVE-2024-4220.