CRITICAL🇵🇱 Wersja polska

CVE-2024-37768

CVSS 9.1v3.1pub. 2024-07-05upd. 2025-03-13

14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.

🤖 AI Analysis
How it works

An attacker sends an HTTP request to the /api/admin/user?id endpoint with the appropriate user identifier, resulting in the user being deleted from the system. The lack of access control mechanisms in handling this request means that the operation can be performed without possessing administrative privileges or any authentication. The vulnerability is remote in nature and requires no interaction from the victim.

Impact

An attacker can permanently delete any user accounts in the system, including administrative accounts, leading to loss of data integrity and potential application unavailability. In extreme cases, it is possible to completely deprive all users of system access.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Temporarily, it is recommended to restrict access to the /api/admin/user endpoint at the firewall or reverse proxy level and enforce strong authentication and authorization controls for all API administrative operations.

Who is affected

14Finger version 1.1 (B1Ackc4T product)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • B1ackc4t 14finger

    APP
    B1Ackc4T
    1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-37770CRITICAL9.1PL ✓same product

RCE w funkcji fingerprint narzędzia 14Finger v1.1

CVE-2024-37767HIGH7.5same product

Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user inf...

CVE-2024-37769HIGH8.8same product

Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator...