CVE-2024-3142
A vulnerability was found in Clavister E10 and E80 up to 14.00.10 and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 14.00.11 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-258917 was assigned to this vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.29%
- Percentil entre todas las CVEs puntuadas: 20
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-352
Referencias
- https://docs.clavister.com/repo/cos-core-release-notes/doc/index.html#d0e2260
- https://github.com/strik3r0x1/Vulns/blob/main/CSRF_Clavister-E80,E10.md
- https://my.clavister.com/downloads/?sid=1
- https://vuldb.com/?ctiid.258917
- https://vuldb.com/?id.258917
- https://vuldb.com/?submit.303530
- https://docs.clavister.com/repo/cos-core-release-notes/doc/index.html#d0e2260
- https://github.com/strik3r0x1/Vulns/blob/main/CSRF_Clavister-E80,E10.md
- https://my.clavister.com/downloads/?sid=1
- https://vuldb.com/?ctiid.258917
- https://vuldb.com/?id.258917
- https://vuldb.com/?submit.303530
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-3142",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-3142",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-04-02T18:25:24.906842Z"
}
}
],
"cvssMetricV2": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cna@vuldb.com",
"affectedData": [
{
"vendor": "Clavister",
"modules": [
"Setting Handler"
],
"product": "E10",
"versions": [
{
"status": "affected",
"version": "14.00.0"
},
{
"status": "affected",
"version": "14.00.1"
},
{
"status": "affected",
"version": "14.00.2"
},
{
"status": "affected",
"version": "14.00.3"
},
{
"status": "affected",
"version": "14.00.4"
},
{
"status": "affected",
"version": "14.00.5"
},
{
"status": "affected",
"version": "14.00.6"
},
{
"status": "affected",
"version": "14.00.7"
},
{
"status": "affected",
"version": "14.00.8"
},
{
"status": "affected",
"version": "14.00.9"
},
{
"status": "affected",
"version": "14.00.10"
}
]
},
{
"vendor": "Clavister",
"modules": [
"Setting Handler"
],
"product": "E80",
"versions": [
{
"status": "affected",
"version": "14.00.0"
},
{
"status": "affected",
"version": "14.00.1"
},
{
"status": "affected",
"version": "14.00.2"
},
{
"status": "affected",
"version": "14.00.3"
},
{
"status": "affected",
"version": "14.00.4"
},
{
"status": "affected",
"version": "14.00.5"
},
{
"status": "affected",
"version": "14.00.6"
},
{
"status": "affected",
"version": "14.00.7"
},
{
"status": "affected",
"version": "14.00.8"
},
{
"status": "affected",
"version": "14.00.9"
},
{
"status": "affected",
"version": "14.00.10"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:clavister:e10:*:*:*:*:*:*:*:*"
],
"vendor": "clavister",
"product": "e10",
"versions": [
{
"status": "affected",
"version": "14.00.0"
},
{
"status": "affected",
"version": "14.00.1"
},
{
"status": "affected",
"version": "14.00.2"
},
{
"status": "affected",
"version": "14.00.3"
},
{
"status": "affected",
"version": "14.00.4"
},
{
"status": "affected",
"version": "14.00.5"
},
{
"status": "affected",
"version": "14.00.6"
},
{
"status": "affected",
"version": "14.00.7"
},
{
"status": "affected",
"version": "14.00.8"
},
{
"status": "affected",
"version": "14.00.9"
},
{
"status": "affected",
"version": "14.00.10"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:clavister:e80:*:*:*:*:*:*:*:*"
],
"vendor": "clavister",
"product": "e80",
"versions": [
{
"status": "affected",
"version": "14.00.0"
},
{
"status": "affected",
"version": "14.00.1"
},
{
"status": "affected",
"version": "14.00.2"
},
{
"status": "affected",
"version": "14.00.3"
},
{
"status": "affected",
"version": "14.00.4"
},
{
"status": "affected",
"version": "14.00.5"
},
{
"status": "affected",
"version": "14.00.6"
},
{
"status": "affected",
"version": "14.00.7"
},
{
"status": "affected",
"version": "14.00.8"
},
{
"status": "affected",
"version": "14.00.9"
},
{
"status": "affected",
"version": "14.00.10"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-04-02T01:15:52.127",
"references": [
{
"url": "https://docs.clavister.com/repo/cos-core-release-notes/doc/index.html#d0e2260",
"source": "cna@vuldb.com"
},
{
"url": "https://github.com/strik3r0x1/Vulns/blob/main/CSRF_Clavister-E80,E10.md",
"source": "cna@vuldb.com"
},
{
"url": "https://my.clavister.com/downloads/?sid=1",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.258917",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.258917",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?submit.303530",
"source": "cna@vuldb.com"
},
{
"url": "https://docs.clavister.com/repo/cos-core-release-notes/doc/index.html#d0e2260",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/strik3r0x1/Vulns/blob/main/CSRF_Clavister-E80,E10.md",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://my.clavister.com/downloads/?sid=1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://vuldb.com/?ctiid.258917",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://vuldb.com/?id.258917",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://vuldb.com/?submit.303530",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in Clavister E10 and E80 up to 14.00.10 and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 14.00.11 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-258917 was assigned to this vulnerability."
},
{
"lang": "es",
"value": "Se encontró una vulnerabilidad en Clavister E10 y E80 hasta 20240323 y se clasificó como problemática. Este problema afecta un procesamiento desconocido del componente Controlador de configuración. La manipulación conduce a cross-site request forgery. El ataque puede iniciarse de forma remota. El exploit ha sido divulgado al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-258917. NOTA: Se contactó primeramente con el proveedor sobre esta divulgación, pero no respondió de ninguna manera."
}
],
"lastModified": "2026-06-17T07:43:23.550",
"sourceIdentifier": "cna@vuldb.com"
}