CVE-2024-28140
Estado: AplazadaMedia (6.1)—
The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user. This can be confirmed by running "ps aux" as the root user and observing the output.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.30%
- Percentil entre todas las CVEs puntuadas: 21
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
CWE
- CWE-250
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-28140",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-28140",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-12-11T17:19:48.898302Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
"affectedData": [
{
"vendor": "Image Access GmbH",
"product": "Scan2Net",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "7.42",
"status": "unaffected"
}
],
"version": "0",
"lessThan": "7.42",
"versionType": "custom"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2024-12-11T16:15:10.050",
"references": [
{
"url": "https://r.sec-consult.com/imageaccess",
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
},
{
"url": "https://www.imageaccess.de/?page=SupportPortal&lang=en",
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
},
{
"url": "http://seclists.org/fulldisclosure/2024/Dec/2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
"description": [
{
"lang": "en",
"value": "CWE-250"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user. This can be confirmed by running \"ps aux\" as the root user and observing the output."
},
{
"lang": "es",
"value": "El dispositivo de escaneo se inicia en modo kiosk de manera predeterminada y abre la interfaz de Scan2Net en una ventana del navegador. Este navegador se ejecuta con los permisos del superusuario. También hay otras aplicaciones ejecutándose como superusuario. Esto se puede confirmar ejecutando \"ps aux\" como superusuario y observando el resultado."
}
],
"lastModified": "2026-06-17T07:21:04.103",
"sourceIdentifier": "551230f0-3615-47bd-b7cc-93e92e730bbf"
}