CVE-2024-10776

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
06/12/2024
Last modified:
06/12/2024

Description

Lua apps can be deployed, removed, started, reloaded or stopped without authorization via<br /> AppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write<br /> files or load apps that use all features of the product available to a customer.