« Volver al listado

CVE-2024-1104

Estado: AnalizadaAlta (7.5)—

Un atacante remoto no autenticado puede eludir el mecanismo de prevención de fuerza bruta y perturbar el servicio web de todos los usuarios.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-1104",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-1104",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-14T15:50:08.852542Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "Areal Topkapi",
          "product": "Webserv2",
          "versions": [
            {
              "status": "affected",
              "version": "6.2.4776"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:areal-topkapi:webserv2:*:*:*:*:*:*:*:*"
          ],
          "vendor": "areal-topkapi",
          "product": "webserv2",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "6.2.4776"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-02-22T12:15:46.033",
  "references": [
    {
      "url": "https://www.areal-topkapi.com/en/services/security-bulletins",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://www.areal-topkapi.com/en/services/security-bulletins",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-307"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb the webservice for all users."
    },
    {
      "lang": "es",
      "value": "Un atacante remoto no autenticado puede eludir el mecanismo de prevención de fuerza bruta y perturbar el servicio web de todos los usuarios."
    }
  ],
  "lastModified": "2026-06-17T07:03:27.263",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:areal-topkapi:webserv2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CB03A06-47B9-4E88-AD01-A64B8E243F9C",
              "versionEndIncluding": "6.2.4776"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "info@cert.vde.com"
}