CRITICAL🇵🇱 Wersja polska

CVE-2024-42919

CVSS 9.8v3.1pub. 2024-08-20upd. 2025-11-12

eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

🤖 AI Analysis
How it works

The vulnerability results from improper implementation of access control mechanisms in the acteScanAVReport module of the eScan management console. An attacker can send a specially crafted network request without the need for authentication, as the application does not properly verify permissions to access this component. The attack vector is network-based, requires no user interaction or special privileges, making this vulnerability particularly dangerous.

Impact

An attacker can gain unauthorized access to sensitive data, modify data or system configuration, and potentially cause service unavailability — corresponding to complete breach of confidentiality, integrity, and availability (C:H/I:H/A:H).

Mitigation & patch

Apply patches available from the vendor according to references. It is also recommended to restrict access to the eScan management console at the network level (firewall) exclusively to trusted IP addresses until the fix is deployed.

Who is affected

eScan Management Console version 14.0.1400.2281

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Escanav Escan Management Console

    APP
    Escanav
    14.0.1400.2281
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-33730CRITICAL9.8PL ✓same product

Privilege Escalation w eScan Management Console — hasła w plain text

CVE-2023-31703CRITICAL9.0PL ✓same product

XSS w formularzu edycji użytkownika eScan Management Console

CVE-2023-31702HIGH7.2same product

SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote att...

CVE-2023-34838MEDIUM5.4same product

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allo...

CVE-2023-34836MEDIUM5.4same product

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allo...