« Volver al listado

CVE-2024-7211

Estado: ModificadaMedia (6.1)—

The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users.

Note: 1E Platform's component utilizing the third-party Duende Identity Server has been updated with the patch that includes the fix.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-7211",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-7211",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-01T17:33:30.440960Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@1e.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@1e.com",
      "affectedData": [
        {
          "vendor": "1E",
          "product": "1E Platform",
          "versions": [
            {
              "status": "affected",
              "version": "24.7"
            },
            {
              "status": "affected",
              "version": "23.11.1.15"
            },
            {
              "status": "affected",
              "version": "23.7.1.80"
            },
            {
              "status": "affected",
              "version": "8.4.1.229"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-08-01T17:16:09.727",
  "references": [
    {
      "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/1e-2024-2001/",
      "source": "security@1e.com"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users.\n\nNote: 1E Platform's component utilizing the third-party Duende Identity Server has been updated with the patch that includes the fix."
    },
    {
      "lang": "es",
      "value": " El servidor de identidad utilizado por 1E Platform podría permitir la redirección de URL a sitios que no son de confianza. Nota: El servidor de identidad en la plataforma 1E se actualizó con el parche necesario."
    }
  ],
  "lastModified": "2026-06-17T08:19:35.693",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:1e:platform:8.4.1.229:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85744E52-16DF-43C6-AD32-9F7900998AB7"
            },
            {
              "criteria": "cpe:2.3:a:1e:platform:23.7.1.80:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4D00FCE-9011-45B2-9BA2-0E2115948E39"
            },
            {
              "criteria": "cpe:2.3:a:1e:platform:23.11.1.15:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA3612F8-C90E-474B-8243-0543BCAAFE7C"
            },
            {
              "criteria": "cpe:2.3:a:1e:platform:24.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68C25D73-241A-4143-AB09-516A54FD1C3A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@1e.com"
}