CVE-2024-10381

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
25/10/2024
Last modified:
14/11/2024

Description

This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable device.<br /> <br /> Successful exploitation of this vulnerability could allow remote attacker to gain unauthorized access and take complete control of the targeted device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:matrixcomsec:cosec_vega_faxq_firmware:*:*:*:*:*:*:*:* v2r17 (excluding)
cpe:2.3:h:matrixcomsec:cosec_vega_faxq:-:*:*:*:*:*:*:*