CRITICAL🇵🇱 Wersja polska

CVE-2024-30802

CVSS 9.8v3.1pub. 2024-05-14upd. 2026-04-15

An issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html component.

🤖 AI Analysis
How it works

An attacker can exploit a vulnerability in the login.html component of the Vehicle Management System to obtain a higher privilege level than they are entitled to. The attack vector is network-based (AV:N), requires no prior privileges (PR:N) or user interaction (UI:N), which means that the attack can be conducted remotely by anyone with access to the system's web interface.

Impact

A successful attack leads to the attacker obtaining elevated privileges in the system, which may result in complete takeover of the application, unauthorized access to vehicle and user data, and violation of system confidentiality, integrity, and availability.

Mitigation & patch

Apply patches available from the manufacturer according to references. Until the update is applied, it is recommended to restrict access to the system's web interface exclusively to trusted networks or IP addresses through firewall or access control mechanisms.

Who is affected

Vehicle Management System version 7.31.0.3_20230412

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References