« Volver al listado

CVE-2024-13061

Estado: AplazadaCrítica (9.8)—

The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de elusión de autenticación (CWE-290) en API remota sin credenciales (AV:N, PR:N, UI:N). Permite obtener tokens de usuarios arbitrarios para acceso no autorizado (T1078) y potencial lectura de datos del sistema (confidencialidad crítica).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-13061",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-13061",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-31T15:12:08.985712Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "twcert@cert.org.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "twcert@cert.org.tw",
      "affectedData": [
        {
          "vendor": "2100 Technology Electronic",
          "product": "Official Document Management System",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5.0.86.9",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-12-31T12:15:22.967",
  "references": [
    {
      "url": "https://www.chtsecurity.com/news/255984da-6630-4e25-ba9b-5ce6933935a6",
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.chtsecurity.com/news/ade9e9af-61d0-4e3c-8aa0-e8524ee2cfbc",
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/en/cp-139-8340-d8b16-2.html",
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-8339-570fa-1.html",
      "source": "twcert@cert.org.tw"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "twcert@cert.org.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-290"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system."
    },
    {
      "lang": "es",
      "value": "Electronic Official Document Management System de 2100 Technology tiene una vulnerabilidad de omisión de autenticación. Aunque el producto aplica una lista blanca de direcciones IP para la API utilizada para consultar tokens de usuarios, los atacantes remotos no autenticados aún pueden engañar al servidor para obtener tokens de usuarios arbitrarios, que luego pueden usarse para iniciar sesión en el sistema."
    }
  ],
  "lastModified": "2026-06-17T07:01:05.167",
  "sourceIdentifier": "twcert@cert.org.tw"
}