CVE-2024-40405

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
13/11/2024
Last modified:
01/05/2025

Description

Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cybelesoft:thinfinity_workspace:*:*:*:*:*:*:*:* 7.0.3.109 (excluding)