CVE-2024-36246

May 31, 2024, 1:01 p.m.

None
No Score

Description

Missing authorization vulnerability exists in Unifier and Unifier Cast Version.5.0 or later, and the patch "20240527" not applied. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be modified or deleted.

Product(s) Impacted

Product Versions
Unifier
  • ['5.0 or later']
Unifier
  • ['5.0 or later as well as the patch 20240527 not applied']

Weaknesses

Common security weaknesses mapped to this vulnerability.

Timeline

Published: May 31, 2024, 6:15 a.m.
Last Modified: May 31, 2024, 1:01 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

vultures@jpcert.or.jp

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.