CVE-2024-7345
Estado: AnalizadaCrítica (9.6)—
Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge LTS platforms up to OpenEdge LTS 11.7.18 and LTS 12.2.13 on all supported release platforms
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 9.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.59%
- Percentil entre todas las CVEs puntuadas: 46
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-94
- CWE-94
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-7345",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-7345",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-09-03T15:06:48.221094Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@progress.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.3,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.6,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@progress.com",
"affectedData": [
{
"vendor": "Progress",
"modules": [
"PASOE Application Server",
"OpenEdge Authentication Gateway"
],
"product": "OpenEdge",
"versions": [
{
"status": "affected",
"version": "11.7.0",
"versionType": "custom",
"lessThanOrEqual": "11.7.19"
},
{
"status": "affected",
"version": "12.2.0",
"versionType": "custom",
"lessThanOrEqual": "12.2.14"
},
{
"status": "unaffected",
"version": "12.8.0",
"versionType": "custom"
}
],
"platforms": [
"Windows",
"Linux",
"64 bit",
"x86",
"32 bit"
],
"defaultStatus": "affected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:*"
],
"vendor": "progress",
"product": "openedge",
"versions": [
{
"status": "affected",
"version": "11.7.0",
"versionType": "custom",
"lessThanOrEqual": "11.7.19"
},
{
"status": "affected",
"version": "12.2.0",
"versionType": "custom",
"lessThanOrEqual": "12.2.14"
},
{
"status": "unaffected",
"version": "12.8.0"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2024-09-03T15:15:16.707",
"references": [
{
"url": "https://community.progress.com/s/article/Direct-local-client-connections-to-MS-Agents-can-bypass-authentication",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "security@progress.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@progress.com",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge LTS platforms up to OpenEdge LTS 11.7.18 and LTS 12.2.13 on all supported release platforms"
},
{
"lang": "es",
"value": "La omisión por parte del cliente ABL local de las comprobaciones de seguridad PASOE requeridas puede permitir que un atacante realice una inyección de código no autorizada en agentes multisesión en plataformas OpenEdge LTS compatibles hasta OpenEdge LTS 11.7.18 y LTS 12.2.13 en todas las plataformas de lanzamiento compatibles"
}
],
"lastModified": "2026-06-17T08:19:54.567",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E38EE20-1A60-46BB-8045-965B60B09B68",
"versionEndIncluding": "11.7.18"
},
{
"criteria": "cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE560C37-3845-4B18-BDDC-38FF65C4CA2C",
"versionEndIncluding": "12.2.13",
"versionStartIncluding": "12.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@progress.com"
}