CVE-2024-51954: Unauthorized access to secure services in ArcGIS Server
There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfederated) ArcGIS Server instance. Successful exploitation results in unauthorized access to protected services outside the attacker’s originally assigned authorization boundary, constituting a scope change. If exploited, this issue would have a high impact on confidentiality, a low impact on integrity, and no impact on the availability of the software.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51954?
CVE-2024-51954 is classified as a moderate severity vulnerability due to improper access control in ArcGIS Server.
How do I fix CVE-2024-51954?
To fix CVE-2024-51954, update Esri ArcGIS Server to the latest version above 11.3 which addresses the access control issue.
Who is affected by CVE-2024-51954?
CVE-2024-51954 affects users of Esri ArcGIS Server versions 10.9.1 through 11.3 on both Windows and Linux platforms.
What type of attack does CVE-2024-51954 allow?
CVE-2024-51954 potentially allows a remote, low privileged authenticated attacker to access secure services.
When was CVE-2024-51954 disclosed?
CVE-2024-51954 was disclosed in 2024 as part of security updates for Esri software products.