CVE-2024-6364: Server Identity Validation Bypass in Absolute Persistence®
A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled attacker with both physical access to the device, and full hostile network control, to initiate OS commands on the device. To remediate this vulnerability, update the device firmware to the latest available version. Please contact the device manufacturer for upgrade instructions or contact Absolute Security, see reference below.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6364?
CVE-2024-6364 is considered to have a moderate severity due to its requirement for physical access and complete network control to exploit.
How do I fix CVE-2024-6364?
To fix CVE-2024-6364, update Absolute Persistence to version 2.8 or later.
What products are affected by CVE-2024-6364?
CVE-2024-6364 affects Absolute Persistence versions prior to 2.8.
What type of access is required to exploit CVE-2024-6364?
Exploiting CVE-2024-6364 requires both physical access to the device and full hostile network control.
What may an attacker be able to do by exploiting CVE-2024-6364?
An attacker exploiting CVE-2024-6364 may be able to initiate OS commands on the affected device.